Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
5.1
ImageMagick: Malicious images can read sensitive memory
CVE-2026-25576
GHSA-jv4p-gjwq-9r2j
CVE-2026-25576
Summary
ImageMagick, a popular image editing software, has a security issue that could allow an attacker to access sensitive memory. If you're using an outdated version of ImageMagick, an attacker could exploit this flaw to gain unauthorized information. Update to version 7.1.2-15 or 6.9.13-40 to fix this issue.
What to do
- Update magick.net-q16-anycpu to version 14.10.3.
- Update magick.net-q16-hdri-anycpu to version 14.10.3.
- Update magick.net-q16-hdri-openmp-arm64 to version 14.10.3.
- Update magick.net-q16-hdri-arm64 to version 14.10.3.
- Update magick.net-q16-hdri-x64 to version 14.10.3.
- Update magick.net-q16-hdri-x86 to version 14.10.3.
- Update magick.net-q16-openmp-arm64 to version 14.10.3.
- Update magick.net-q16-openmp-x64 to version 14.10.3.
- Update magick.net-q16-openmp-x86 to version 14.10.3.
- Update magick.net-q16-arm64 to version 14.10.3.
- Update magick.net-q16-x64 to version 14.10.3.
- Update magick.net-q16-x86 to version 14.10.3.
- Update magick.net-q8-anycpu to version 14.10.3.
- Update magick.net-q8-openmp-arm64 to version 14.10.3.
- Update magick.net-q8-x64 to version 14.10.3.
- Update magick.net-q8-x86 to version 14.10.3.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| – | magick.net-q16-anycpu | <= 14.10.3 | 14.10.3 |
| – | magick.net-q16-hdri-anycpu | <= 14.10.3 | 14.10.3 |
| – | magick.net-q16-hdri-openmp-arm64 | <= 14.10.3 | 14.10.3 |
| – | magick.net-q16-hdri-arm64 | <= 14.10.3 | 14.10.3 |
| – | magick.net-q16-hdri-x64 | <= 14.10.3 | 14.10.3 |
| – | magick.net-q16-hdri-x86 | <= 14.10.3 | 14.10.3 |
| – | magick.net-q16-openmp-arm64 | <= 14.10.3 | 14.10.3 |
| – | magick.net-q16-openmp-x64 | <= 14.10.3 | 14.10.3 |
| – | magick.net-q16-openmp-x86 | <= 14.10.3 | 14.10.3 |
| – | magick.net-q16-arm64 | <= 14.10.3 | 14.10.3 |
| – | magick.net-q16-x64 | <= 14.10.3 | 14.10.3 |
| – | magick.net-q16-x86 | <= 14.10.3 | 14.10.3 |
| – | magick.net-q8-anycpu | <= 14.10.3 | 14.10.3 |
| – | magick.net-q8-openmp-arm64 | <= 14.10.3 | 14.10.3 |
| – | magick.net-q8-x64 | <= 14.10.3 | 14.10.3 |
| – | magick.net-q8-x86 | <= 14.10.3 | 14.10.3 |
| imagemagick | imagemagick | <= 6.9.13-40 | – |
| imagemagick | imagemagick | > 7.0.0-0 , <= 7.1.2-15 | – |
| dlemstra | magick.net | <= 14.10.3 | – |
Original title
ImageMagick: Out of bounds read in multiple coders read raw pixel data
Original description
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in multiple raw image format handles. The vulnerability occurs when processing images with -extract dimensions larger than -size dimensions, causing out-of-bounds memory reads from a heap-allocated buffer. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
nvd CVSS3.1
5.5
Vulnerability type
CWE-122
Heap-based Buffer Overflow
- https://nvd.nist.gov/vuln/detail/CVE-2026-25576
- https://github.com/advisories/GHSA-jv4p-gjwq-9r2j
- https://github.com/ImageMagick/ImageMagick/commit/077b42643212d7da8c1a4f6b2cd006... Patch
- https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-jv4p-gjwq-9r... Vendor Advisory
- https://github.com/dlemstra/Magick.NET/releases/tag/14.10.3 Product Release Notes
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25576... Vendor Advisory
Published: 24 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026