CVE-2026-28494
published 2026-03-10CVE-2026-28494: ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a stack buffer…
PriorityP432high7.1CVSS 3.1
AVLACLPRNUIRSUCNIHAH
EPSS
0.11%
1.4th percentile
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a stack buffer overflow exists in ImageMagick's morphology kernel parsing functions. User-controlled kernel strings exceeding a buffer are copied into fixed-size stack buffers via memcpy without bounds checking, resulting in stack corruption. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imagemagick | < imagemagick 8:7.1.2.16+dfsg1-1 (forky) | imagemagick 8:7.1.2.16+dfsg1-1 (forky) |
| imagemagick | imagemagick | < 6.9.13-41 | 6.9.13-41 |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | >= 0 < 8:7.1.1.43+dfsg1-1+deb13u7 | 8:7.1.1.43+dfsg1-1+deb13u7 |
| imagemagick | imagemagick | >= 0 < 8:7.1.2.16+dfsg1-1 | 8:7.1.2.16+dfsg1-1 |
| imagemagick | imagemagick | >= 7.0.0-0 < 7.1.2-16 | 7.1.2-16 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ImageMagick: ImageMagick: Arbitrary code execution or denial of service via maliciously crafted kernel strings
vendor_redhat·2026-03-09·CVSS 7.1
CVE-2026-28494 [HIGH] CWE-120 ImageMagick: ImageMagick: Arbitrary code execution or denial of service via maliciously crafted kernel strings
ImageMagick: ImageMagick: Arbitrary code execution or denial of service via maliciously crafted kernel strings
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a stack buffer overflow exists in ImageMagick's morphology kernel parsing functions. User-controlled kernel strings exceeding a buffer are copied into fixed-size stack buffers via memcpy without bounds checking, resulting in stack corruption. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
A flaw was found in ImageMagick. This vulnerability, a stack buffer overflow, allows an attacker to cause stack corruption by providing maliciously crafted kernel strings. This can lead to arbitrary code execution or a denial of service (DoS), impactin
Debian
CVE-2026-28494: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
vendor_debian·2026·CVSS 7.1
CVE-2026-28494 [HIGH] CVE-2026-28494: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a stack buffer overflow exists in ImageMagick's morphology kernel parsing functions. User-controlled kernel strings exceeding a buffer are copied into fixed-size stack buffers via memcpy without bounds checking, resulting in stack corruption. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 8:7.1.2.16+dfsg1-1)
sid: resolved (fixed in 8:7.1.2.16+dfsg1-1)
trixie: resolved (fixed in 8:7.1.1.43+dfsg1-1+deb13u7)
VulDB
ImageMagick up to 6.9.13-40/7.1.2-15 stack-based overflow (EUVD-2026-10373 / Nessus ID 303080)
vuldb·2026-04-22·CVSS 7.1
CVE-2026-28494 [HIGH] ImageMagick up to 6.9.13-40/7.1.2-15 stack-based overflow (EUVD-2026-10373 / Nessus ID 303080)
A vulnerability identified as critical has been detected in ImageMagick up to 6.9.13-40/7.1.2-15. Affected by this vulnerability is an unknown functionality. This manipulation causes stack-based buffer overflow.
This vulnerability is registered as CVE-2026-28494. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
GHSA
ImageMagick vulnerable to stack corruption through long morphology kernel names or arrays
ghsa·2026-03-12
CVE-2026-28494 [HIGH] CWE-121 ImageMagick vulnerable to stack corruption through long morphology kernel names or arrays
ImageMagick vulnerable to stack corruption through long morphology kernel names or arrays
A stack buffer overflow exists in ImageMagick's morphology kernel parsing functions. User-controlled kernel strings exceeding a buffer are copied into fixed-size stack buffers via memcpy without bounds checking, resulting in stack corruption.
OSV
ImageMagick vulnerable to stack corruption through long morphology kernel names or arrays
osv·2026-03-12
CVE-2026-28494 [HIGH] ImageMagick vulnerable to stack corruption through long morphology kernel names or arrays
ImageMagick vulnerable to stack corruption through long morphology kernel names or arrays
A stack buffer overflow exists in ImageMagick's morphology kernel parsing functions. User-controlled kernel strings exceeding a buffer are copied into fixed-size stack buffers via memcpy without bounds checking, resulting in stack corruption.
OSV
CVE-2026-28494: ImageMagick is free and open-source software used for editing and manipulating digital images
osv·2026-03-10·CVSS 7.1
CVE-2026-28494 [HIGH] CVE-2026-28494: ImageMagick is free and open-source software used for editing and manipulating digital images
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a stack buffer overflow exists in ImageMagick's morphology kernel parsing functions. User-controlled kernel strings exceeding a buffer are copied into fixed-size stack buffers via memcpy without bounds checking, resulting in stack corruption. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
No detection rules found.
No public exploits indexed.
2026-03-10
Published