Executive brief
ImageMagick is a widely used software suite for displaying, converting, and editing image files. A vulnerability was found where processing a specially crafted XML file can cause the software to write data outside of its intended memory area. This could lead to a service crash or unpredictable behavior, potentially impacting the availability of applications that use ImageMagick to process user-uploaded content.
Technical details
A heap-based buffer overflow (CWE-122) and integer underflow (CWE-191) exist in ImageMagick's XML parsing logic. When processing a malformed XML file, the application may perform an out-of-bounds write of a single zero byte. This vulnerability can be triggered remotely without authentication or user interaction if the application processes untrusted XML input. An attacker could potentially cause a denial-of-service (DoS) condition. The issue is addressed in ImageMagick version 7.1.2-19 and Magick.NET version 14.12.0.
Affected products
- ImageMagick ImageMagick < 7.1.2-19
- dlemstra Magick.NET < 14.12.0
Timeline
- 2026-04-13: disclosed
- 2026-04-13: advisory
- 2026-04-13: patched: Fixed in ImageMagick 7.1.2-19 and Magick.NET 14.12.0