Junglewise Threat Intelligence

CVE-2026-46523: ImageMagick heap use-after-free in MSL decoder

CVE-2026-46523 · Severity: medium · CVSS 6.2 · Published 2026-06-10

Technologies: Magick.NET-Q16-OpenMP-arm64 (NuGet), Magick.NET-Q16-AnyCPU (NuGet), Magick.NET-Q16-HDRI-AnyCPU (NuGet), Magick.NET-Q8-x86 (NuGet), Magick.NET-Q8-AnyCPU (NuGet), Magick.NET-Q16-arm64 (NuGet), Magick.NET-Q16-OpenMP-x64 (NuGet), Magick.NET-Q16-HDRI-OpenMP-x64 (NuGet), Magick.NET-Q16-HDRI-arm64 (NuGet), Magick.NET-Q16-HDRI-x86 (NuGet), Magick.NET-Q16-HDRI-x64 (NuGet), Magick.NET-Q8-OpenMP-arm64 (NuGet), ImageMagick, Magick.NET-Q8-OpenMP-x64 (NuGet), Magick.NET-Q16-x64 (NuGet), Magick.NET-Q8-arm64 (NuGet), Magick.NET-Q8-x64 (NuGet), Magick.NET-Q16-x86 (NuGet), Magick.NET-Q16-HDRI-OpenMP-arm64 (NuGet). Vendors: NuGet, ImageMagick.

Executive brief

ImageMagick is a widely used open-source tool for editing and converting digital images. A flaw in how it processes specific image script files (MSL) could allow an attacker to crash the software or disrupt operations. This could lead to a denial-of-service for applications that rely on ImageMagick to process user-uploaded images.

Technical details

A heap-based use-after-free vulnerability exists in the Magick Scripting Language (MSL) decoder of ImageMagick. The vulnerability is triggered when processing a specially crafted MSL image file, leading to memory corruption. An attacker with the ability to provide a malicious MSL file to the library can cause a denial-of-service (application crash). The issue is identified as CWE-416 and affects versions prior to 7.1.2-23 and 6.9.13-48. Patches have been released in versions 7.1.2-23 and 6.9.13-48 to address the root cause in the MSL decoder.

Affected products

  • ImageMagick ImageMagick < 7.1.2-23, < 6.9.13-48

Timeline

  • 2026-05-17: advisory: GitHub Security Advisory published
  • 2026-06-10: disclosed: NVD publication date

References

Related threats