Junglewise Threat Intelligence

CVE-2026-40311: ImageMagick heap use-after-free in XMP profile processing

CVE-2026-40311 · Severity: medium · CVSS 5.5 · Published 2026-04-14

Technologies: Magick.NET-Q16-OpenMP-arm64 (NuGet), Magick.NET-Q16-AnyCPU (NuGet), Magick.NET-Q16-HDRI-AnyCPU (NuGet), Magick.NET-Q8-x86 (NuGet), Magick.NET-Q8-AnyCPU (NuGet), Magick.NET-Q16-arm64 (NuGet), Magick.NET-Q16-OpenMP-x64 (NuGet), Magick.NET-Q16-HDRI-arm64 (NuGet), Magick.NET-Q16-HDRI-x86 (NuGet), Magick.NET-Q16-HDRI-x64 (NuGet), Magick.NET-Q8-OpenMP-arm64 (NuGet), ImageMagick, Dlemstra Magick.NET, Magick.NET-Q16-x64 (NuGet), Magick.NET-Q8-arm64 (NuGet), Magick.NET-Q8-x64 (NuGet), Magick.NET-Q16-x86 (NuGet), Magick.NET-Q16-HDRI-OpenMP-arm64 (NuGet). Vendors: NuGet, ImageMagick, Dlemstra.

Executive brief

ImageMagick is a widely used software suite for editing and manipulating digital images. A vulnerability has been identified where processing a specially crafted image with an invalid XMP metadata profile can cause the application to crash. This could lead to a denial-of-service condition for services or automated workflows that process user-supplied images.

Technical details

A heap use-after-free vulnerability exists in ImageMagick's MagickCore/property.c component. The issue occurs when the software attempts to read and subsequently print values from an invalid XMP (Extensible Metadata Platform) profile. An attacker can exploit this by providing a malformed image file that, when processed by a vulnerable version of ImageMagick or its wrappers like Magick.NET, triggers the use-after-free condition. This results in memory corruption and a crash (denial of service). The vulnerability is addressed in ImageMagick versions 7.1.2-19 and 6.9.13-44, and Magick.NET version 14.12.0.

Affected products

  • ImageMagick ImageMagick < 7.1.2-19, < 6.9.13-44
  • dlemstra Magick.NET < 14.12.0

Timeline

  • 2026-04-12: patched: ImageMagick 7.1.2-19 released
  • 2026-04-13: disclosed: NVD publication date
  • 2026-04-14: advisory: GitHub Advisory published

References

Related threats