Executive brief
ImageMagick is a widely used software suite for editing and manipulating digital images. A vulnerability has been identified where processing a specially crafted image with an invalid XMP metadata profile can cause the application to crash. This could lead to a denial-of-service condition for services or automated workflows that process user-supplied images.
Technical details
A heap use-after-free vulnerability exists in ImageMagick's MagickCore/property.c component. The issue occurs when the software attempts to read and subsequently print values from an invalid XMP (Extensible Metadata Platform) profile. An attacker can exploit this by providing a malformed image file that, when processed by a vulnerable version of ImageMagick or its wrappers like Magick.NET, triggers the use-after-free condition. This results in memory corruption and a crash (denial of service). The vulnerability is addressed in ImageMagick versions 7.1.2-19 and 6.9.13-44, and Magick.NET version 14.12.0.
Affected products
- ImageMagick ImageMagick < 7.1.2-19, < 6.9.13-44
- dlemstra Magick.NET < 14.12.0
Timeline
- 2026-04-12: patched: ImageMagick 7.1.2-19 released
- 2026-04-13: disclosed: NVD publication date
- 2026-04-14: advisory: GitHub Advisory published
References
- https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-r83h-crwp-3vm7
- https://github.com/ImageMagick/ImageMagick/commit/5facfecf1abb3fed46a08f614dcc43d1e548e20d
- https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-19
- https://github.com/dlemstra/Magick.NET/releases/tag/14.12.0
- https://api.github.com/repos/ImageMagick/ImageMagick/security-advisories/GHSA-r83h-crwp-3vm7