Severity
7.1HIGH
EPSS
0.0%
top 96.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 10
Latest updateMar 12

Description

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a stack buffer overflow exists in ImageMagick's morphology kernel parsing functions. User-controlled kernel strings exceeding a buffer are copied into fixed-size stack buffers via memcpy without bounds checking, resulting in stack corruption. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:HExploitability: 1.8 | Impact: 5.2

Affected Packages22 packages

CVEListV5imagemagick/imagemagick< 6.9.13-41+1
NVDimagemagick/imagemagick7.0.0-07.1.2-16+1
Debianimagemagick< 8:7.1.1.43+dfsg1-1+deb13u7+1
NuGetMagick.NET-Q8-OpenMP-x64< 14.10.4
NuGetMagick.NET-Q16-OpenMP-x64< 14.10.4

🔴Vulnerability Details

4
GHSA
ImageMagick vulnerable to stack corruption through long morphology kernel names or arrays2026-03-12
OSV
ImageMagick vulnerable to stack corruption through long morphology kernel names or arrays2026-03-12
OSV
CVE-2026-28494: ImageMagick is free and open-source software used for editing and manipulating digital images2026-03-10
CVEList
ImageMagick affected by stack corruption through long morphology kernel names or arrays2026-03-09

📋Vendor Advisories

2
Red Hat
ImageMagick: ImageMagick: Arbitrary code execution or denial of service via maliciously crafted kernel strings2026-03-09
Debian
CVE-2026-28494: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-28494 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-28494 (HIGH CVSS 7.1) | ImageMagick is free and open-source | cvebase.io