Junglewise Threat Intelligence

CVE-2026-33899: ImageMagick heap buffer overflow in XML parsing

CVE-2026-33899 · Severity: medium · CVSS 5.3 · Published 2026-04-13

Technologies: Magick.NET-Q16-OpenMP-arm64 (NuGet), Magick.NET-Q16-AnyCPU (NuGet), Dlemstra Magick.NET, Magick.NET-Q16-HDRI-AnyCPU (NuGet), Magick.NET-Q8-x86 (NuGet), Magick.NET-Q8-AnyCPU (NuGet), Magick.NET-Q16-arm64 (NuGet), Magick.NET-Q16-OpenMP-x64 (NuGet), Magick.NET-Q16-HDRI-arm64 (NuGet), Magick.NET-Q16-HDRI-x86 (NuGet), Magick.NET-Q16-HDRI-x64 (NuGet), Magick.NET-Q8-OpenMP-arm64 (NuGet), ImageMagick, Magick.NET-Q8-OpenMP-x64 (NuGet), Magick.NET-Q16-x64 (NuGet), Magick.NET-Q8-arm64 (NuGet), Magick.NET-Q8-x64 (NuGet), Magick.NET-Q16-x86 (NuGet), Magick.NET-Q16-HDRI-OpenMP-arm64 (NuGet). Vendors: NuGet, Dlemstra, ImageMagick.

Executive brief

ImageMagick is a widely used software suite for displaying, converting, and editing image files. A vulnerability was found where processing a specially crafted XML file can cause the software to write data outside of its intended memory area. This could lead to a service crash or unpredictable behavior, potentially impacting the availability of applications that use ImageMagick to process user-uploaded content.

Technical details

A heap-based buffer overflow (CWE-122) and integer underflow (CWE-191) exist in ImageMagick's XML parsing logic. When processing a malformed XML file, the application may perform an out-of-bounds write of a single zero byte. This vulnerability can be triggered remotely without authentication or user interaction if the application processes untrusted XML input. An attacker could potentially cause a denial-of-service (DoS) condition. The issue is addressed in ImageMagick version 7.1.2-19 and Magick.NET version 14.12.0.

Affected products

  • ImageMagick ImageMagick < 7.1.2-19
  • dlemstra Magick.NET < 14.12.0

Timeline

  • 2026-04-13: disclosed
  • 2026-04-13: advisory
  • 2026-04-13: patched: Fixed in ImageMagick 7.1.2-19 and Magick.NET 14.12.0

References

Related threats