Junglewise Threat Intelligence

CVE-2026-33901: ImageMagick heap buffer overflow in MVG decoder

CVE-2026-33901 · Severity: high · CVSS 7.5 · Published 2026-04-13

Technologies: Red Hat Enterprise Linux 7, Magick.NET-Q16-OpenMP-arm64 (NuGet), Magick.NET-Q16-AnyCPU (NuGet), Magick.NET-Q16-HDRI-AnyCPU (NuGet), Red Hat Enterprise Linux 6, Magick.NET-Q8-x86 (NuGet), Magick.NET-Q8-AnyCPU (NuGet), Magick.NET-Q16-arm64 (NuGet), Magick.NET-Q16-OpenMP-x64 (NuGet), Magick.NET-Q16-HDRI-arm64 (NuGet), Magick.NET-Q16-HDRI-x86 (NuGet), Magick.NET-Q16-HDRI-x64 (NuGet), Magick.NET-Q8-OpenMP-arm64 (NuGet), ImageMagick, Dlemstra Magick.NET, Magick.NET-Q8-OpenMP-x64 (NuGet), Magick.NET-Q16-x64 (NuGet), Magick.NET-Q8-arm64 (NuGet), Magick.NET-Q8-x64 (NuGet), Magick.NET-Q16-x86 (NuGet), Magick.NET-Q16-HDRI-OpenMP-arm64 (NuGet). Vendors: Red Hat, NuGet, ImageMagick, Dlemstra.

Executive brief

ImageMagick, a widely used open-source tool for image processing, is vulnerable to a flaw that occurs when handling specially crafted image files. An attacker could exploit this to cause a denial-of-service condition, potentially crashing applications or services that rely on ImageMagick to process user-uploaded images. This could disrupt business operations and service availability for platforms that automate image manipulation.

Technical details

A heap-based buffer overflow (CWE-122) exists in the MVG (Magick Vector Graphics) decoder of ImageMagick. The vulnerability is located in the RenderMVGContent function within MagickCore/draw.c, where insufficient bounds checking on the 'q' and 'p' pointers can lead to an out-of-bounds write. A remote, unauthenticated attacker can exploit this by providing a specially crafted image file for processing. Successful exploitation primarily impacts service availability by causing a crash (Denial of Service). The issue is resolved in ImageMagick versions 7.1.2-19 and 6.9.13-44.

Affected products

  • ImageMagick ImageMagick < 7.1.2-19, < 6.9.13-44
  • Red Hat Red Hat Enterprise Linux 6 affected
  • Red Hat Red Hat Enterprise Linux 7 affected

Timeline

  • 2026-04-13: disclosed
  • 2026-04-13: advisory
  • 2026-04-13: patched

References

Related threats