Junglewise Threat Intelligence

CVE-2026-40312: ImageMagick off-by-one error in MSL decoder

CVE-2026-40312 · Severity: medium · CVSS 6.2 · Published 2026-04-14

Technologies: Magick.NET-Q16-OpenMP-arm64 (NuGet), Magick.NET-Q16-AnyCPU (NuGet), Dlemstra Magick.NET, Magick.NET-Q16-HDRI-AnyCPU (NuGet), Magick.NET-Q8-x86 (NuGet), Magick.NET-Q8-AnyCPU (NuGet), Magick.NET-Q16-arm64 (NuGet), Magick.NET-Q16-OpenMP-x64 (NuGet), Magick.NET-Q16-HDRI-arm64 (NuGet), Magick.NET-Q16-HDRI-x86 (NuGet), Magick.NET-Q16-HDRI-x64 (NuGet), Magick.NET-Q8-OpenMP-arm64 (NuGet), ImageMagick, Magick.NET-Q8-OpenMP-x64 (NuGet), Magick.NET-Q16-x64 (NuGet), Magick.NET-Q8-arm64 (NuGet), Magick.NET-Q8-x64 (NuGet), Magick.NET-Q16-x86 (NuGet), Magick.NET-Q16-HDRI-OpenMP-arm64 (NuGet). Vendors: NuGet, Dlemstra, ImageMagick.

Executive brief

ImageMagick, a widely used suite for displaying and converting images, is vulnerable to a flaw when processing specific script files. An attacker can provide a specially crafted Magick Scripting Language (MSL) file that causes the application to crash. This can lead to a denial-of-service, interrupting business operations that rely on automated image processing.

Technical details

An off-by-one error (CWE-193) exists in the Magick Scripting Language (MSL) decoder of ImageMagick. The vulnerability is triggered when the library attempts to read and parse a maliciously crafted .msl file. This is a local attack vector requiring no special privileges or user interaction beyond the application attempting to process the file. Successful exploitation results in a memory corruption that leads to an application crash (Denial of Service). The issue has been addressed in ImageMagick version 7.1.2-19 and Magick.NET version 14.12.0.

Affected products

  • ImageMagick ImageMagick < 7.1.2-19
  • dlemstra Magick.NET < 14.12.0

Timeline

  • 2026-04-13: advisory: NVD publication date
  • 2026-04-14: disclosed: GitHub Advisory published
  • 2026-04-14: patched: GitHub Advisory reviewed and updated with patch information

References

Related threats