CVE-2026-28493
published 2026-03-10CVE-2026-28493: ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, an integer overflow vulnerability…
PriorityP337medium6.5CVSS 3.1
AVNACHPRNUINSUCNILAH
EPSS
0.19%
9.4th percentile
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, an integer overflow vulnerability exists in the SIXEL decoer. The vulnerability allows an attacker to perform an out of bounds via a specially crafted image. This vulnerability is fixed in 7.1.2-16.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imagemagick | < imagemagick 8:7.1.2.16+dfsg1-1 (forky) | imagemagick 8:7.1.2.16+dfsg1-1 (forky) |
| imagemagick | imagemagick | < 7.1.2-16 | 7.1.2-16 |
| imagemagick | imagemagick | >= 0 < 8:7.1.1.43+dfsg1-1+deb13u7 | 8:7.1.1.43+dfsg1-1+deb13u7 |
| imagemagick | imagemagick | >= 0 < 8:7.1.2.16+dfsg1-1 | 8:7.1.2.16+dfsg1-1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
ImageMagick up to 7.1.2-15 SIXEL Decoder integer overflow (EUVD-2026-10371 / Nessus ID 303080)
vuldb·2026-04-21·CVSS 6.5
CVE-2026-28493 [MEDIUM] ImageMagick up to 7.1.2-15 SIXEL Decoder integer overflow (EUVD-2026-10371 / Nessus ID 303080)
A vulnerability, which was classified as critical, has been found in ImageMagick up to 7.1.2-15. The affected element is an unknown function of the component SIXEL Decoder. This manipulation causes integer overflow.
This vulnerability is handled as CVE-2026-28493. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
GHSA
ImageMagick has Integer Overflow leading to out of bounds write in SIXEL decoder
ghsa·2026-03-12
CVE-2026-28493 [MEDIUM] CWE-190 ImageMagick has Integer Overflow leading to out of bounds write in SIXEL decoder
ImageMagick has Integer Overflow leading to out of bounds write in SIXEL decoder
An integer overflow vulnerability exists in the SIXEL decoer. The vulnerability allows an attacker to perform an out of bounds via a specially crafted mage.
OSV
ImageMagick has Integer Overflow leading to out of bounds write in SIXEL decoder
osv·2026-03-12
CVE-2026-28493 [MEDIUM] ImageMagick has Integer Overflow leading to out of bounds write in SIXEL decoder
ImageMagick has Integer Overflow leading to out of bounds write in SIXEL decoder
An integer overflow vulnerability exists in the SIXEL decoer. The vulnerability allows an attacker to perform an out of bounds via a specially crafted mage.
OSV
CVE-2026-28493: ImageMagick is free and open-source software used for editing and manipulating digital images
osv·2026-03-10·CVSS 6.5
CVE-2026-28493 [MEDIUM] CVE-2026-28493: ImageMagick is free and open-source software used for editing and manipulating digital images
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, an integer overflow vulnerability exists in the SIXEL decoer. The vulnerability allows an attacker to perform an out of bounds via a specially crafted image. This vulnerability is fixed in 7.1.2-16.
Red Hat
ImageMagick: ImageMagick: Denial of Service and information disclosure via integer overflow in SIXEL decoder
vendor_redhat·2026-03-09·CVSS 6.5
CVE-2026-28493 [MEDIUM] CWE-190 ImageMagick: ImageMagick: Denial of Service and information disclosure via integer overflow in SIXEL decoder
ImageMagick: ImageMagick: Denial of Service and information disclosure via integer overflow in SIXEL decoder
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, an integer overflow vulnerability exists in the SIXEL decoer. The vulnerability allows an attacker to perform an out of bounds via a specially crafted image. This vulnerability is fixed in 7.1.2-16.
A flaw was found in ImageMagick. An integer overflow vulnerability exists in the SIXEL decoder, which allows a remote attacker to perform an out-of-bounds write via a specially crafted image. This can lead to a Denial of Service (DoS) and potentially information disclosure.
Statement: This MODERATE impact vulnerability affects ImageMagick in Red Hat Enterprise Lin
Debian
CVE-2026-28493: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
vendor_debian·2026·CVSS 6.5
CVE-2026-28493 [MEDIUM] CVE-2026-28493: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, an integer overflow vulnerability exists in the SIXEL decoer. The vulnerability allows an attacker to perform an out of bounds via a specially crafted image. This vulnerability is fixed in 7.1.2-16.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 8:7.1.2.16+dfsg1-1)
sid: resolved (fixed in 8:7.1.2.16+dfsg1-1)
trixie: resolved (fixed in 8:7.1.1.43+dfsg1-1+deb13u7)
No detection rules found.
No public exploits indexed.
2026-03-10
Published