CVE-2026-30937
published 2026-03-10CVE-2026-30937: ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a 32-bit unsigned…
PriorityP429medium6.1CVSS 3.1
AVLACLPRLUINSUCNILAH
EPSS
0.10%
1.0th percentile
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a 32-bit unsigned integer overflow in the XWD (X Windows) encoder can cause an undersized heap buffer allocation. When writing a extremely large image an out of bounds heap write can occur. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imagemagick | < imagemagick 8:7.1.2.16+dfsg1-1 (forky) | imagemagick 8:7.1.2.16+dfsg1-1 (forky) |
| imagemagick | imagemagick | < 6.9.13-41 | 6.9.13-41 |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | >= 0 < 8:7.1.1.43+dfsg1-1+deb13u7 | 8:7.1.1.43+dfsg1-1+deb13u7 |
| imagemagick | imagemagick | >= 0 < 8:7.1.2.16+dfsg1-1 | 8:7.1.2.16+dfsg1-1 |
| imagemagick | imagemagick | >= 7.0.0-0 < 7.1.2-16 | 7.1.2-16 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
osv6.1MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
ImageMagick up to 6.9.13-40/7.1.2-15 XWD Encoder heap-based overflow (EUVD-2026-10402 / Nessus ID 303080)
vuldb·2026-04-22·CVSS 6.1
CVE-2026-30937 [MEDIUM] ImageMagick up to 6.9.13-40/7.1.2-15 XWD Encoder heap-based overflow (EUVD-2026-10402 / Nessus ID 303080)
A vulnerability was found in ImageMagick up to 6.9.13-40/7.1.2-15. It has been classified as critical. Affected is an unknown function of the component XWD Encoder. The manipulation leads to heap-based buffer overflow.
This vulnerability is referenced as CVE-2026-30937. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
OSV
ImageMagick has heap buffer overflow in WriteXWDImage due to CARD32 arithmetic overflow in bytes_per_line calculation
osv·2026-03-12
CVE-2026-30937 [MEDIUM] ImageMagick has heap buffer overflow in WriteXWDImage due to CARD32 arithmetic overflow in bytes_per_line calculation
ImageMagick has heap buffer overflow in WriteXWDImage due to CARD32 arithmetic overflow in bytes_per_line calculation
A 32-bit unsigned integer overflow in the XWD (X Windows) encoder can cause an undersized heap buffer allocation. When writing a extremely large image an out of bounds heap write can occur.
```
==741961==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x5020000083dc at pc 0x56553b4c4245 bp 0x7ffd9d20fef0 sp 0x7ffd9d20fee0
WRITE of size 1 at 0x5020000083dc thread T0
```
GHSA
ImageMagick has heap buffer overflow in WriteXWDImage due to CARD32 arithmetic overflow in bytes_per_line calculation
ghsa·2026-03-12
CVE-2026-30937 [MEDIUM] CWE-122 ImageMagick has heap buffer overflow in WriteXWDImage due to CARD32 arithmetic overflow in bytes_per_line calculation
ImageMagick has heap buffer overflow in WriteXWDImage due to CARD32 arithmetic overflow in bytes_per_line calculation
A 32-bit unsigned integer overflow in the XWD (X Windows) encoder can cause an undersized heap buffer allocation. When writing a extremely large image an out of bounds heap write can occur.
```
==741961==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x5020000083dc at pc 0x56553b4c4245 bp 0x7ffd9d20fef0 sp 0x7ffd9d20fee0
WRITE of size 1 at 0x5020000083dc thread T0
```
OSV
CVE-2026-30937: ImageMagick is free and open-source software used for editing and manipulating digital images
osv·2026-03-10·CVSS 6.1
CVE-2026-30937 [MEDIUM] CVE-2026-30937: ImageMagick is free and open-source software used for editing and manipulating digital images
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a 32-bit unsigned integer overflow in the XWD (X Windows) encoder can cause an undersized heap buffer allocation. When writing a extremely large image an out of bounds heap write can occur. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
Red Hat
ImageMagick: ImageMagick: Denial of Service via integer overflow in XWD encoder
vendor_redhat·2026-03-09·CVSS 6.8
CVE-2026-30937 [MEDIUM] CWE-190 ImageMagick: ImageMagick: Denial of Service via integer overflow in XWD encoder
ImageMagick: ImageMagick: Denial of Service via integer overflow in XWD encoder
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a 32-bit unsigned integer overflow in the XWD (X Windows) encoder can cause an undersized heap buffer allocation. When writing a extremely large image an out of bounds heap write can occur. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
A flaw was found in ImageMagick, a software suite for editing and manipulating digital images. An integer overflow vulnerability exists in the XWD (X Windows) encoder when processing extremely large images. This flaw can lead to an undersized memory allocation, resulting in an out-of-bounds write to the heap. A local attacker could ex
Debian
CVE-2026-30937: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
vendor_debian·2026·CVSS 6.8
CVE-2026-30937 [MEDIUM] CVE-2026-30937: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a 32-bit unsigned integer overflow in the XWD (X Windows) encoder can cause an undersized heap buffer allocation. When writing a extremely large image an out of bounds heap write can occur. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 8:7.1.2.16+dfsg1-1)
sid: resolved (fixed in 8:7.1.2.16+dfsg1-1)
trixie: resolved (fixed in 8:7.1.1.43+dfsg1-1+deb13u7)
No detection rules found.
No public exploits indexed.
2026-03-10
Published