Technology · NuGet
Magick.NET-Q16-AnyCPU (NuGet) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 186 vulnerabilities in Magick.NET-Q16-AnyCPU (NuGet): 0 in the last 7 days and 50 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, ImageMagick memory leak in CLI invalid options, was published on 2 September 2026.
- Last 7 days
- 0
- Last 90 days
- 50
- Critical, all time
- 0
- Exploited in the wild
- 0
About Magick.NET-Q16-AnyCPU (NuGet)
A .NET library for ImageMagick using 16 bits per pixel, compiled for any CPU architecture.
Latest Magick.NET-Q16-AnyCPU (NuGet) vulnerabilities
- ImageMagick memory leak in CLI invalid optionslowCVSS 3.3
- CVE-2026-62946: ImageMagick integer overflow in JNX decodermediumCVSS 5.1EPSS 0.1%
- CVE-2026-62363: ImageMagick heap buffer overflow in fx operationmediumCVSS 5EPSS 0.1%
- CVE-2026-62343: ImageMagick heap buffer overwrite in morphology operationmediumCVSS 4.7EPSS 0.1%
- CVE-2026-66011: ImageMagick memory leak in magick CLI via invalid optionslowCVSS 3.3EPSS 0.1%
- ImageMagick heap buffer overflow in X11 importlowCVSS 1.8
- ImageMagick memory leak in ICON decoderlowCVSS 3.7
- ImageMagick memory leak in VIFF encoderlowCVSS 2.9
- ImageMagick memory leak in YUV decoderlowCVSS 3.7
- ImageMagick memory leak in TIFF encoderlowCVSS 2.9
- ImageMagick memory leak in JNG encoderlowCVSS 2.9
- ImageMagick memory leak in hough lines operationlowCVSS 2.9
- ImageMagick memory leak in TIFF encoderlowCVSS 2.9
- ImageMagick: Code injection in HTML encoder due to incomplete fix oflowCVSS 3.1
- ImageMagick: Policy Bypass due to an incomplete fix oflowCVSS 3.1
- CVE-2026-61872: ImageMagick memory leak in TIFF encoderlowCVSS 3.1EPSS 0.1%
- CVE-2026-61871: ImageMagick memory leak in ICON decoderlowCVSS 3.7EPSS 0.4%
- CVE-2026-61868: ImageMagick memory leak in YUV decoderlowCVSS 3.7EPSS 0.4%
- CVE-2026-61867: ImageMagick memory leak in TIFF encoderlowCVSS 3.1EPSS 0.1%
- CVE-2026-61866: ImageMagick memory leak in JNG encoderlowCVSS 3.1EPSS 0.3%
- CVE-2026-61865: ImageMagick memory leak in hough lines operationlowCVSS 3.1EPSS 0.1%
- CVE-2026-61864: ImageMagick memory leak in log colorspace transformationlowCVSS 3.1EPSS 0.1%
- CVE-2026-61863: ImageMagick memory leak in TIFF encoderlowCVSS 3.1EPSS 0.3%
- CVE-2026-61862: ImageMagick out-of-bounds read in identify commandlowCVSS 3.1EPSS 0.1%
- CVE-2026-61860: ImageMagick use-after-free in FreeType initializationlowCVSS 3.7EPSS 0.4%
Most severe Magick.NET-Q16-AnyCPU (NuGet) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-25965: ImageMagick path traversal policy bypass in path security policyhighCVSS 8.6EPSS 0.8%
- CVE-2026-25794: ImageMagick heap overflow in WriteUHDRImagehighCVSS 8.2EPSS 0.6%
- CVE-2026-28693: ImageMagick integer overflow in DIB coderhighCVSS 8.1EPSS 0.6%
- CVE-2026-46522: ImageMagick infinite loop in MIFF decoderhighCVSS 7.5EPSS 1.9%
- CVE-2026-33901: ImageMagick heap buffer overflow in MVG decoderhighCVSS 7.5EPSS 0.7%
- CVE-2026-33908: ImageMagick uncontrolled recursion in DestroyXMLTree functionhighCVSS 7.5EPSS 0.7%
- CVE-2026-25985: ImageMagick excessive memory allocation in SVG decoderhighCVSS 7.5EPSS 0.7%
- CVE-2026-53461: ImageMagick heap overflow in ICON decoderhighCVSS 7.5EPSS 0.6%
- CVE-2026-53460: ImageMagick denial of service in AcquireAlignedMemoryhighCVSS 7.5EPSS 0.6%
- CVE-2026-49218: ImageMagick denial of service in DCM decoderhighCVSS 7.5EPSS 0.6%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 12 | 0 | |
| 6 Jul 2026 | 10 | 0 | |
| 13 Jul 2026 | 13 | 0 | |
| 20 Jul 2026 | 11 | 0 | |
| 27 Jul 2026 | 3 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 1 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/magick-net-q16-anycpu.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Magick.NET-Q16-AnyCPU (NuGet) vulnerabilities", https://junglewise.ai/threats/technologies/magick-net-q16-anycpu, 26 September 2026.