Junglewise Threat Intelligence

CVE-2026-33905: ImageMagick out-of-bounds read in sample operation

CVE-2026-33905 · Severity: medium · CVSS 5.5 · Published 2026-04-13

Technologies: Magick.NET-Q16-OpenMP-arm64 (NuGet), Magick.NET-Q16-AnyCPU (NuGet), Dlemstra Magick.NET, Magick.NET-Q16-HDRI-AnyCPU (NuGet), Magick.NET-Q8-x86 (NuGet), Magick.NET-Q8-AnyCPU (NuGet), Magick.NET-Q16-arm64 (NuGet), Magick.NET-Q16-OpenMP-x64 (NuGet), Magick.NET-Q16-HDRI-arm64 (NuGet), Magick.NET-Q16-HDRI-x86 (NuGet), Magick.NET-Q16-HDRI-x64 (NuGet), Magick.NET-Q8-OpenMP-arm64 (NuGet), ImageMagick, Magick.NET-Q8-OpenMP-x64 (NuGet), Magick.NET-Q16-x64 (NuGet), Magick.NET-Q8-arm64 (NuGet), Magick.NET-Q8-x64 (NuGet), Magick.NET-Q16-x86 (NuGet), Magick.NET-Q16-HDRI-OpenMP-arm64 (NuGet). Vendors: NuGet, Dlemstra, ImageMagick.

Executive brief

ImageMagick is a widely used software suite for displaying, converting, and editing image files. A vulnerability was found in its image sampling operation that could allow a specially crafted image to crash the application. This could lead to a denial-of-service, impacting the availability of services that rely on ImageMagick for automated image processing.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in ImageMagick's '-sample' operation. The flaw is triggered when a specific offset is provided through the 'sample:offset' define, leading the application to read memory outside of the intended buffer. This is a local attack that requires user interaction, such as a user or automated process attempting to process a malicious image file. Successful exploitation can lead to an application crash (Denial of Service). The issue is addressed in ImageMagick version 7.1.2-19 and Magick.NET version 14.12.0.

Affected products

  • ImageMagick ImageMagick < 7.1.2-19
  • dlemstra Magick.NET < 14.12.0

Timeline

  • 2026-04-13: disclosed
  • 2026-04-13: patched
  • 2026-04-14: advisory

References

Related threats