Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.3

ImageMagick Crashes When Handling Malformed MSL Files

CVE-2026-28687 GHSA-fpvf-frm6-625q
Summary

An attacker can cause ImageMagick to crash by creating a specific type of malformed file. This could lead to a denial-of-service (crash) situation. Update to the latest version of ImageMagick to prevent this issue.

What to do
  • Update magick.net-q16-anycpu to version 14.10.4.
  • Update magick.net-q16-hdri-anycpu to version 14.10.4.
  • Update magick.net-q16-hdri-openmp-arm64 to version 14.10.4.
  • Update magick.net-q16-hdri-arm64 to version 14.10.4.
  • Update magick.net-q16-hdri-x64 to version 14.10.4.
  • Update magick.net-q16-hdri-x86 to version 14.10.4.
  • Update magick.net-q16-openmp-arm64 to version 14.10.4.
  • Update magick.net-q16-openmp-x64 to version 14.10.4.
  • Update magick.net-q16-openmp-x86 to version 14.10.4.
  • Update magick.net-q16-arm64 to version 14.10.4.
  • Update magick.net-q16-x64 to version 14.10.4.
  • Update magick.net-q16-x86 to version 14.10.4.
  • Update magick.net-q16-hdri-openmp-x64 to version 14.10.4.
  • Update magick.net-q8-anycpu to version 14.10.4.
  • Update magick.net-q8-openmp-arm64 to version 14.10.4.
  • Update magick.net-q8-openmp-x64 to version 14.10.4.
  • Update magick.net-q8-arm64 to version 14.10.4.
  • Update magick.net-q8-x64 to version 14.10.4.
  • Update magick.net-q8-x86 to version 14.10.4.
Affected software
VendorProductAffected versionsFix available
magick.net-q16-anycpu <= 14.10.4 14.10.4
magick.net-q16-hdri-anycpu <= 14.10.4 14.10.4
magick.net-q16-hdri-openmp-arm64 <= 14.10.4 14.10.4
magick.net-q16-hdri-arm64 <= 14.10.4 14.10.4
magick.net-q16-hdri-x64 <= 14.10.4 14.10.4
magick.net-q16-hdri-x86 <= 14.10.4 14.10.4
magick.net-q16-openmp-arm64 <= 14.10.4 14.10.4
magick.net-q16-openmp-x64 <= 14.10.4 14.10.4
magick.net-q16-openmp-x86 <= 14.10.4 14.10.4
magick.net-q16-arm64 <= 14.10.4 14.10.4
magick.net-q16-x64 <= 14.10.4 14.10.4
magick.net-q16-x86 <= 14.10.4 14.10.4
magick.net-q16-hdri-openmp-x64 <= 14.10.4 14.10.4
magick.net-q8-anycpu <= 14.10.4 14.10.4
magick.net-q8-openmp-arm64 <= 14.10.4 14.10.4
magick.net-q8-openmp-x64 <= 14.10.4 14.10.4
magick.net-q8-arm64 <= 14.10.4 14.10.4
magick.net-q8-x64 <= 14.10.4 14.10.4
magick.net-q8-x86 <= 14.10.4 14.10.4
imagemagick imagemagick <= 6.9.13-41
imagemagick imagemagick > 7.0.0-0 , <= 7.1.2-16
Original title
ImageMagick has Heap Use-After-Free in ImageMagick MSL decoder
Original description
A heap use-after-free vulnerability in ImageMagick's MSL decoder allows an attacker to trigger access to freed memory by crafting an MSL file.

```
=================================================================
==1500633==ERROR: AddressSanitizer: heap-use-after-free on address 0x527000011550 at pc 0x5612583fa212 bp 0x7ffedb86d160 sp 0x7ffedb86d150
READ of size 8 at 0x527000011550 thread T0
```
nvd CVSS3.1 5.3
Vulnerability type
CWE-416 Use After Free
Published: 12 Mar 2026 · Updated: 13 Mar 2026 · First seen: 10 Mar 2026