Junglewise Threat Intelligence

CVE-2026-48733: ImageMagick infinite loop in subimage-search

CVE-2026-48733 · Severity: medium · CVSS 4.7 · Published 2026-06-10

Technologies: Magick.NET-Q16-OpenMP-arm64 (NuGet), Magick.NET-Q16-AnyCPU (NuGet), Magick.NET-Q16-HDRI-AnyCPU (NuGet), Magick.NET-Q8-x86 (NuGet), Magick.NET-Q8-AnyCPU (NuGet), Magick.NET-Q16-arm64 (NuGet), Magick.NET-Q16-OpenMP-x64 (NuGet), Magick.NET-Q16-HDRI-arm64 (NuGet), Magick.NET-Q16-HDRI-x86 (NuGet), Magick.NET-Q16-HDRI-x64 (NuGet), Magick.NET-Q8-OpenMP-arm64 (NuGet), Magick.NET-Q8-OpenMP-x64 (NuGet), Magick.NET-Q16-x64 (NuGet), Magick.NET-Q8-arm64 (NuGet), Magick.NET-Q8-x64 (NuGet), Magick.NET-Q16-x86 (NuGet), Magick.NET-Q16-HDRI-OpenMP-arm64 (NuGet). Vendors: ImageMagick, NuGet.

Executive brief

ImageMagick is a widely used software suite for displaying, converting, and editing images. A vulnerability in its subimage-search feature allows a specially crafted image to trigger an infinite loop, which can cause the application to stop responding. This could lead to a denial-of-service condition, impacting the availability of systems that process user-supplied images.

Technical details

A vulnerability classified as CWE-835 (Loop with Unreachable Exit Condition) exists in ImageMagick's subimage-search operation. The flaw is triggered when the software processes a specially crafted image, leading to an infinite loop that consumes system resources. The attack vector is local and requires user interaction, such as a user opening or processing a malicious image file. This results in a high impact on availability (Denial of Service) but does not affect confidentiality or integrity. The issue is addressed in Magick.NET version 14.14.0.

Affected products

  • ImageMagick Magick.NET-Q16-AnyCPU < 14.14.0
  • ImageMagick Magick.NET-Q16-HDRI-AnyCPU < 14.14.0
  • ImageMagick Magick.NET-Q16-HDRI-OpenMP-arm64 < 14.14.0
  • ImageMagick Magick.NET-Q16-HDRI-arm64 < 14.14.0
  • ImageMagick Magick.NET-Q16-HDRI-x64 < 14.14.0
  • ImageMagick Magick.NET-Q16-HDRI-x86 < 14.14.0
  • ImageMagick Magick.NET-Q16-OpenMP-arm64 < 14.14.0
  • ImageMagick Magick.NET-Q16-OpenMP-x64 < 14.14.0
  • ImageMagick Magick.NET-Q16-arm64 < 14.14.0
  • ImageMagick Magick.NET-Q16-x64 < 14.14.0
  • ImageMagick Magick.NET-Q16-x86 < 14.14.0
  • ImageMagick Magick.NET-Q8-AnyCPU < 14.14.0
  • ImageMagick Magick.NET-Q8-OpenMP-arm64 < 14.14.0
  • ImageMagick Magick.NET-Q8-OpenMP-x64 < 14.14.0
  • ImageMagick Magick.NET-Q8-arm64 < 14.14.0
  • ImageMagick Magick.NET-Q8-x64 < 14.14.0
  • ImageMagick Magick.NET-Q8-x86 < 14.14.0

Timeline

  • 2026-05-30: disclosed
  • 2026-06-10: advisory: NVD publication date
  • 2026-06-25: advisory: GitHub Advisory published

References

Related threats