Executive brief
ImageMagick is a widely used software suite for displaying, converting, and editing image files. A vulnerability in its DICOM (DCM) image decoder allows for the creation of images with invalid dimensions, which can bypass security policies and cause application crashes. This could lead to a denial-of-service, impacting the availability of services that process user-uploaded medical or technical images.
Technical details
A vulnerability exists in the ImageMagick DCM (DICOM) decoder due to improper input validation (CWE-20). A missing check allows the decoder to process images with invalid dimensions, which can bypass security policies and trigger crashes during subsequent image operations. The attack can be executed remotely over a network without authentication or user interaction. This results in a high impact on availability (Denial of Service). The issue is addressed in Magick.NET version 14.14.0.
Affected products
- ImageMagick Magick.NET-Q16-AnyCPU < 14.14.0
- ImageMagick Magick.NET-Q16-HDRI-AnyCPU < 14.14.0
- ImageMagick Magick.NET-Q16-HDRI-OpenMP-arm64 < 14.14.0
- ImageMagick Magick.NET-Q16-HDRI-arm64 < 14.14.0
- ImageMagick Magick.NET-Q16-HDRI-x64 < 14.14.0
- ImageMagick Magick.NET-Q16-HDRI-x86 < 14.14.0
- ImageMagick Magick.NET-Q16-OpenMP-arm64 < 14.14.0
- ImageMagick Magick.NET-Q16-OpenMP-x64 < 14.14.0
- ImageMagick Magick.NET-Q16-arm64 < 14.14.0
- ImageMagick Magick.NET-Q16-x64 < 14.14.0
- ImageMagick Magick.NET-Q16-x86 < 14.14.0
- ImageMagick Magick.NET-Q8-AnyCPU < 14.14.0
- ImageMagick Magick.NET-Q8-OpenMP-arm64 < 14.14.0
- ImageMagick Magick.NET-Q8-OpenMP-x64 < 14.14.0
- ImageMagick Magick.NET-Q8-arm64 < 14.14.0
- ImageMagick Magick.NET-Q8-x64 < 14.14.0
- ImageMagick Magick.NET-Q8-x86 < 14.14.0
Timeline
- 2026-05-30: disclosed: Initial disclosure by dlemstra
- 2026-06-10: advisory: NVD publication date
- 2026-06-25: advisory: GitHub Advisory reviewed and updated