Junglewise Threat Intelligence

CVE-2026-55510: ImageMagick use-after-free in 8BIM profile processing

CVE-2026-55510 · Severity: medium · CVSS 5.5 · Published 2026-07-01

Technologies: Magick.NET-Q16-OpenMP-arm64 (NuGet), Magick.NET-Q16-AnyCPU (NuGet), Magick.NET-Q16-HDRI-AnyCPU (NuGet), Magick.NET-Q8-x86 (NuGet), Magick.NET-Q8-AnyCPU (NuGet), Magick.NET-Q16-arm64 (NuGet), Magick.NET-Q16-OpenMP-x64 (NuGet), Magick.NET-Q16-HDRI-arm64 (NuGet), Magick.NET-Q16-HDRI-x86 (NuGet), Magick.NET-Q16-HDRI-x64 (NuGet), Magick.NET-Q8-OpenMP-arm64 (NuGet), Magick.NET-Q8-OpenMP-x64 (NuGet), Magick.NET-Q16-x64 (NuGet), Magick.NET-Q8-arm64 (NuGet), Magick.NET-Q8-x64 (NuGet), Magick.NET-Q16-x86 (NuGet), Magick.NET-Q16-HDRI-OpenMP-arm64 (NuGet). Vendors: NuGet, ImageMagick.

Executive brief

ImageMagick is a widely used software suite for displaying, converting, and editing image files. A vulnerability has been identified where processing a specially crafted image file can cause the application to crash or behave unexpectedly. This could lead to a denial-of-service, impacting the availability of services that rely on ImageMagick for automated image processing.

Technical details

A use-after-free vulnerability exists in ImageMagick when identifying an image containing a crafted 8BIM profile with a specific format string. The flaw is triggered during the image identification process, where the application references memory that has already been released. An attacker can exploit this by providing a malicious image file to a system using the Magick.NET library. Successful exploitation typically results in a crash (denial of service), though use-after-free bugs can sometimes lead to arbitrary code execution under specific memory conditions. The issue is resolved in Magick.NET version 14.15.0.

Affected products

  • ImageMagick Magick.NET < 14.15.0

Timeline

  • 2026-06-26: disclosed: Initial disclosure by dlemstra
  • 2026-07-01: advisory: NVD publication
  • 2026-07-24: patched: GitHub Advisory reviewed and updated with patch information

References

Related threats