Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.5

ImageMagick's JBIG Decoder Can Crash or Cause Data Corruption

CVE-2026-28691 GHSA-wj8w-pjxf-9g4f
Summary

The JBIG decoder in ImageMagick has a flaw that can cause a crash or data corruption when processing certain image files. This could lead to unintended consequences, such as data loss or system instability. Update ImageMagick to the latest version to fix this issue.

What to do
  • Update magick.net-q16-anycpu to version 14.10.4.
  • Update magick.net-q16-hdri-anycpu to version 14.10.4.
  • Update magick.net-q16-hdri-openmp-arm64 to version 14.10.4.
  • Update magick.net-q16-hdri-arm64 to version 14.10.4.
  • Update magick.net-q16-hdri-x64 to version 14.10.4.
  • Update magick.net-q16-hdri-x86 to version 14.10.4.
  • Update magick.net-q16-openmp-arm64 to version 14.10.4.
  • Update magick.net-q16-openmp-x64 to version 14.10.4.
  • Update magick.net-q16-openmp-x86 to version 14.10.4.
  • Update magick.net-q16-arm64 to version 14.10.4.
  • Update magick.net-q16-x64 to version 14.10.4.
  • Update magick.net-q16-x86 to version 14.10.4.
  • Update magick.net-q16-hdri-openmp-x64 to version 14.10.4.
  • Update magick.net-q8-anycpu to version 14.10.4.
  • Update magick.net-q8-openmp-arm64 to version 14.10.4.
  • Update magick.net-q8-openmp-x64 to version 14.10.4.
  • Update magick.net-q8-arm64 to version 14.10.4.
  • Update magick.net-q8-x64 to version 14.10.4.
  • Update magick.net-q8-x86 to version 14.10.4.
Affected software
VendorProductAffected versionsFix available
imagemagick imagemagick <= 6.9.13-41
imagemagick imagemagick > 7.0.0-0 , <= 7.1.2-16
magick.net-q16-anycpu <= 14.10.4 14.10.4
magick.net-q16-hdri-anycpu <= 14.10.4 14.10.4
magick.net-q16-hdri-openmp-arm64 <= 14.10.4 14.10.4
magick.net-q16-hdri-arm64 <= 14.10.4 14.10.4
magick.net-q16-hdri-x64 <= 14.10.4 14.10.4
magick.net-q16-hdri-x86 <= 14.10.4 14.10.4
magick.net-q16-openmp-arm64 <= 14.10.4 14.10.4
magick.net-q16-openmp-x64 <= 14.10.4 14.10.4
magick.net-q16-openmp-x86 <= 14.10.4 14.10.4
magick.net-q16-arm64 <= 14.10.4 14.10.4
magick.net-q16-x64 <= 14.10.4 14.10.4
magick.net-q16-x86 <= 14.10.4 14.10.4
magick.net-q16-hdri-openmp-x64 <= 14.10.4 14.10.4
magick.net-q8-anycpu <= 14.10.4 14.10.4
magick.net-q8-openmp-arm64 <= 14.10.4 14.10.4
magick.net-q8-openmp-x64 <= 14.10.4 14.10.4
magick.net-q8-arm64 <= 14.10.4 14.10.4
magick.net-q8-x64 <= 14.10.4 14.10.4
magick.net-q8-x86 <= 14.10.4 14.10.4
Original title
ImageMagick has uninitialized pointer dereference in JBIG decoder
Original description
An uninitialized pointer dereference vulnerability exists in the JBIG decoder due to a missing check.
nvd CVSS3.1 7.5
Vulnerability type
CWE-252
CWE-824
Published: 12 Mar 2026 · Updated: 13 Mar 2026 · First seen: 10 Mar 2026