CVE-2026-26284
published 2026-02-24CVE-2026-26284: ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick lacks…
PriorityP354critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.40%
32.8th percentile
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick lacks proper boundary checking when processing Huffman-coded data from PCD (Photo CD) files. The decoder contains an function that has an incorrect initialization that could cause an out of bounds read. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imagemagick | < imagemagick 8:7.1.2.15+dfsg1-1 (forky) | imagemagick 8:7.1.2.15+dfsg1-1 (forky) |
| imagemagick | imagemagick | < 6.9.13-40 | 6.9.13-40 |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | >= 0 < 8:7.1.1.43+dfsg1-1+deb13u6 | 8:7.1.1.43+dfsg1-1+deb13u6 |
| imagemagick | imagemagick | >= 0 < 8:7.1.2.15+dfsg1-1 | 8:7.1.2.15+dfsg1-1 |
| imagemagick | imagemagick | >= 0 < 8:6.7.7.10-6ubuntu3.13+esm19 | 8:6.7.7.10-6ubuntu3.13+esm19 |
| imagemagick | imagemagick | >= 0 < 8:6.8.9.9-7ubuntu5.16+esm18 | 8:6.8.9.9-7ubuntu5.16+esm18 |
| imagemagick | imagemagick | >= 0 < 8:6.9.7.4+dfsg-16ubuntu6.15+esm10 | 8:6.9.7.4+dfsg-16ubuntu6.15+esm10 |
| imagemagick | imagemagick | >= 0 < 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm8 | 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm8 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm8 | 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm8 |
| imagemagick | imagemagick | >= 0 < 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm7 | 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm7 |
| imagemagick | imagemagick | >= 7.0.0-0 < 7.1.2-15 | 7.1.2-15 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
osv9.8CRITICAL
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
ImageMagick: Heap overflow in pcd decoder leads to out of bounds read.
osv·2026-03-12
CVE-2026-26284 [MEDIUM] ImageMagick: Heap overflow in pcd decoder leads to out of bounds read.
ImageMagick: Heap overflow in pcd decoder leads to out of bounds read.
The pcd coder lacks proper boundary checking when processing Huffman-coded data. The decoder contains an function that has an incorrect initialization that could cause an out of bounds read.
```
==3900053==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x502000003c6c at pc 0x55601b9cc552 bp 0x7ffd904b1f70 sp 0x7ffd904b1f60
READ of size 1 at 0x502000003c6c thread T0
```
GHSA
ImageMagick: Heap overflow in pcd decoder leads to out of bounds read.
ghsa·2026-03-12
CVE-2026-26284 [MEDIUM] CWE-122 ImageMagick: Heap overflow in pcd decoder leads to out of bounds read.
ImageMagick: Heap overflow in pcd decoder leads to out of bounds read.
The pcd coder lacks proper boundary checking when processing Huffman-coded data. The decoder contains an function that has an incorrect initialization that could cause an out of bounds read.
```
==3900053==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x502000003c6c at pc 0x55601b9cc552 bp 0x7ffd904b1f70 sp 0x7ffd904b1f60
READ of size 1 at 0x502000003c6c thread T0
```
OSV
imagemagick vulnerabilities
osv·2026-03-04·CVSS 9.8
CVE-2026-25897 [CRITICAL] imagemagick vulnerabilities
imagemagick vulnerabilities
It was discovered that ImageMagick did not properly decode certain SUN
image files. An attacker could use this issue to cause ImageMagick to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2026-25897)
It was discovered that ImageMagick did not properly validate pixel index
values when writing UIL and XPM image files. An attacker could use this issue
to cause ImageMagick to crash, resulting in a denial of service, or possibly
obtain sensitive information. (CVE-2026-25898)
It was discovered that ImageMagick's MSL decoder did not properly handle
certain attribute values. An attacker could use this issue to cause ImageMagick
to crash, resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2026-25968)
It was d
OSV
CVE-2026-26284: ImageMagick is free and open-source software used for editing and manipulating digital images
osv·2026-02-24·CVSS 9.1
CVE-2026-26284 [CRITICAL] CVE-2026-26284: ImageMagick is free and open-source software used for editing and manipulating digital images
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick lacks proper boundary checking when processing Huffman-coded data from PCD (Photo CD) files. The decoder contains an function that has an incorrect initialization that could cause an out of bounds read. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2026-03-04·CVSS 6.5
CVE-2026-25968 [MEDIUM] ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: Several security issues were fixed in ImageMagick.
It was discovered that ImageMagick did not properly decode certain SUN
image files. An attacker could use this issue to cause ImageMagick to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2026-25897)
It was discovered that ImageMagick did not properly validate pixel index
values when writing UIL and XPM image files. An attacker could use this issue
to cause ImageMagick to crash, resulting in a denial of service, or possibly
obtain sensitive information. (CVE-2026-25898)
It was discovered that ImageMagick's MSL decoder did not properly handle
certain attribute values. An attacker could use this issue to cause ImageMagick
to crash, resulting in a denial of ser
Red Hat
ImageMagick: ImageMagick: Out-of-bounds read via crafted Photo CD (PCD) files
vendor_redhat·2026-02-24·CVSS 6.5
CVE-2026-26284 [MEDIUM] CWE-131 ImageMagick: ImageMagick: Out-of-bounds read via crafted Photo CD (PCD) files
ImageMagick: ImageMagick: Out-of-bounds read via crafted Photo CD (PCD) files
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick lacks proper boundary checking when processing Huffman-coded data from PCD (Photo CD) files. The decoder contains an function that has an incorrect initialization that could cause an out of bounds read. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
A flaw was found in ImageMagick, a free and open-source software used for editing and manipulating digital images. When processing Huffman-coded data from Photo CD (PCD) files, the image decoder contains an incorrect initialization that could lead to an out-of-bounds read. This vulnerability could allow a remote attac
Debian
CVE-2026-26284: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
vendor_debian·2026·CVSS 6.5
CVE-2026-26284 [MEDIUM] CVE-2026-26284: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick lacks proper boundary checking when processing Huffman-coded data from PCD (Photo CD) files. The decoder contains an function that has an incorrect initialization that could cause an out of bounds read. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 8:7.1.2.15+dfsg1-1)
sid: resolved (fixed in 8:7.1.2.15+dfsg1-1)
trixie: resolved (fixed in 8:7.1.1.43+dfsg1-1+deb13u6)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-26284 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-26284 [MEDIUM] CVE-2026-26284 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-26284 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick lacks proper boundary checking when processing Huffman-coded data from PCD (Photo CD) files. The decoder contains an function that has an incorrect initialization that could cause an out of bounds read. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
Source : NVD
## 9.1
Score
Published February 24, 2026
Severity CRITICAL
CNA Score 6.5
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.9
Exploitation Probability (EPSS) N/A
Affected packages
Bugzilla
CVE-2026-13606 GraphicsMagick: GraphicsMagick: Memory corruption via crafted Photo CD (PCD) file [fedora-all]
bugzilla·2026-06-29·CVSS 9.1
CVE-2026-13606 [CRITICAL] CVE-2026-13606 GraphicsMagick: GraphicsMagick: Memory corruption via crafted Photo CD (PCD) file [fedora-all]
CVE-2026-13606 GraphicsMagick: GraphicsMagick: Memory corruption via crafted Photo CD (PCD) file [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
GraphicsMagick's PCD decoder allocated the per-channel Huffman decode buffers at an exact fit (columns*rows + 1 byte) and advanced the write pointer in the decode loop with an unbounded "q++" and no per-write bound check. A crafted PCD file can drive the pointer past the end of the allocation, producing an attacker-controlled out-of-bounds write (and a preceding out-of-bounds read at the same site). This is the un-ported write-side half of ImageMagick's harden
Bugzilla
CVE-2026-13606 GraphicsMagick: GraphicsMagick: Memory corruption via crafted Photo CD (PCD) file [epel-all]
bugzilla·2026-06-29·CVSS 9.1
CVE-2026-13606 [CRITICAL] CVE-2026-13606 GraphicsMagick: GraphicsMagick: Memory corruption via crafted Photo CD (PCD) file [epel-all]
CVE-2026-13606 GraphicsMagick: GraphicsMagick: Memory corruption via crafted Photo CD (PCD) file [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
GraphicsMagick's PCD decoder allocated the per-channel Huffman decode buffers at an exact fit (columns*rows + 1 byte) and advanced the write pointer in the decode loop with an unbounded "q++" and no per-write bound check. A crafted PCD file can drive the pointer past the end of the allocation, producing an attacker-controlled out-of-bounds write (and a preceding out-of-bounds read at the same site). This is the un-ported write-side half of ImageMagick's hardenin
Bugzilla
CVE-2026-13606 GraphicsMagick: GraphicsMagick: Memory corruption via crafted Photo CD (PCD) file
bugzilla·2026-06-29·CVSS 9.1
CVE-2026-13606 [CRITICAL] CVE-2026-13606 GraphicsMagick: GraphicsMagick: Memory corruption via crafted Photo CD (PCD) file
CVE-2026-13606 GraphicsMagick: GraphicsMagick: Memory corruption via crafted Photo CD (PCD) file
GraphicsMagick's PCD decoder allocated the per-channel Huffman decode buffers at an exact fit (columns*rows + 1 byte) and advanced the write pointer in the decode loop with an unbounded "q++" and no per-write bound check. A crafted PCD file can drive the pointer past the end of the allocation, producing an attacker-controlled out-of-bounds write (and a preceding out-of-bounds read at the same site). This is the un-ported write-side half of ImageMagick's hardening for CVE-2026-26284: GraphicsMagick had ported ImageMagick's out-of-bounds READ fix (changeset 44292e321682) but not the per-write bound and buffer over-allocation, leaving the write path unguarded. The upstream fix over-provisions the
2026-02-24
Published