CVE-2026-32636
published 2026-03-18CVE-2026-32636: ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-17 and 6.9.13-42, the NewXMLTree method contains…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.47%
38.0th percentile
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-17 and 6.9.13-42, the NewXMLTree method contains a bug that could result in a crash due to an out of write bounds of a single zero byte. Versions 7.1.2-17 and 6.9.13-42 fix the issue.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imagemagick | < imagemagick 8:7.1.2.18+dfsg1-1 (forky) | imagemagick 8:7.1.2.18+dfsg1-1 (forky) |
| imagemagick | imagemagick | < 7.1.2-17 | 7.1.2-17 |
| imagemagick | imagemagick | < 6.9.13-42 | 6.9.13-42 |
| imagemagick | imagemagick | >= 0 < 8:7.1.2.18+dfsg1-1 | 8:7.1.2.18+dfsg1-1 |
| imagemagick | imagemagick | >= 0 < 8:6.7.7.10-6ubuntu3.13+esm20 | 8:6.7.7.10-6ubuntu3.13+esm20 |
| imagemagick | imagemagick | >= 0 < 8:6.8.9.9-7ubuntu5.16+esm19 | 8:6.8.9.9-7ubuntu5.16+esm19 |
| imagemagick | imagemagick | >= 0 < 8:6.9.7.4+dfsg-16ubuntu6.15+esm11 | 8:6.9.7.4+dfsg-16ubuntu6.15+esm11 |
| imagemagick | imagemagick | >= 0 < 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm9 | 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm9 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm9 | 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm9 |
| imagemagick | imagemagick | >= 0 < 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm8 | 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm8 |
| imagemagick | imagemagick | >= 7.0.0-0 < 7.1.2-17 | 7.1.2-17 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_ubuntu6.5MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
ImageMagick up to 6.9.13-41/7.1.2-16 Image Parser NewXMLTree out-of-bounds write (GHSA-gc62-2v5p-qpmp / Nessus ID 307507)
vuldb·2026-04-20·CVSS 7.5
CVE-2026-32636 [HIGH] ImageMagick up to 6.9.13-41/7.1.2-16 Image Parser NewXMLTree out-of-bounds write (GHSA-gc62-2v5p-qpmp / Nessus ID 307507)
A vulnerability has been found in ImageMagick up to 6.9.13-41/7.1.2-16 and classified as critical. Affected by this issue is the function NewXMLTree of the component Image Parser. Performing a manipulation results in out-of-bounds write.
This vulnerability is reported as CVE-2026-32636. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
OSV
imagemagick vulnerabilities
osv·2026-03-30·CVSS 7.5
CVE-2026-23952 [HIGH] imagemagick vulnerabilities
imagemagick vulnerabilities
It was discovered that ImageMagick did not properly process certain tags
prior to an image being loaded. An attacker could possibly use this issue
to cause ImageMagick to crash, resulting in a denial of service.
(CVE-2026-23952)
It was discovered that ImageMagick did not properly handle temporary file
creation failures. An attacker could possibly use this issue to cause
ImageMagick to crash, resulting in a denial of service. (CVE-2026-25795)
It was discovered that ImageMagick did not properly manage memory under
certain conditions. An attacker could possibly use this issue to cause
ImageMagick to consume resources, resulting in a denial of service.
(CVE-2026-25796)
It was discovered that ImageMagick incorrectly handled certain specially
crafted image files.
OSV
CVE-2026-32636: ImageMagick is free and open-source software used for editing and manipulating digital images
osv·2026-03-18·CVSS 7.5
CVE-2026-32636 [HIGH] CVE-2026-32636: ImageMagick is free and open-source software used for editing and manipulating digital images
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-17 and 6.9.13-42, the NewXMLTree method contains a bug that could result in a crash due to an out of write bounds of a single zero byte. Versions 7.1.2-17 and 6.9.13-42 fix the issue.
GHSA
ImageMagick has a heap-buffer-overflow in NewXMLTree which could result in crash
ghsa·2026-03-17
CVE-2026-32636 [MEDIUM] CWE-787 ImageMagick has a heap-buffer-overflow in NewXMLTree which could result in crash
ImageMagick has a heap-buffer-overflow in NewXMLTree which could result in crash
The NewXMLTree method contains a bug that could result in a crash due to an out of write bounds of a single zero byte.
OSV
ImageMagick has a heap-buffer-overflow in NewXMLTree which could result in crash
osv·2026-03-17
CVE-2026-32636 [MEDIUM] ImageMagick has a heap-buffer-overflow in NewXMLTree which could result in crash
ImageMagick has a heap-buffer-overflow in NewXMLTree which could result in crash
The NewXMLTree method contains a bug that could result in a crash due to an out of write bounds of a single zero byte.
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2026-03-30·CVSS 6.5
CVE-2026-25799 [MEDIUM] ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: Several security issues were fixed in ImageMagick.
It was discovered that ImageMagick did not properly process certain tags
prior to an image being loaded. An attacker could possibly use this issue
to cause ImageMagick to crash, resulting in a denial of service.
(CVE-2026-23952)
It was discovered that ImageMagick did not properly handle temporary file
creation failures. An attacker could possibly use this issue to cause
ImageMagick to crash, resulting in a denial of service. (CVE-2026-25795)
It was discovered that ImageMagick did not properly manage memory under
certain conditions. An attacker could possibly use this issue to cause
ImageMagick to consume resources, resulting in a denial of service.
(CVE-2026-25796)
It was discovered that Ima
Red Hat
ImageMagick: ImageMagick: Denial of Service via out-of-bounds write in NewXMLTree method
vendor_redhat·2026-03-18·CVSS 5.3
CVE-2026-32636 [MEDIUM] CWE-787 ImageMagick: ImageMagick: Denial of Service via out-of-bounds write in NewXMLTree method
ImageMagick: ImageMagick: Denial of Service via out-of-bounds write in NewXMLTree method
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-17 and 6.9.13-42, the NewXMLTree method contains a bug that could result in a crash due to an out of write bounds of a single zero byte. Versions 7.1.2-17 and 6.9.13-42 fix the issue.
A flaw was found in ImageMagick. The NewXMLTree method contains a bug that could result in a crash due to an out of write bounds of a single zero byte. This vulnerability could allow a remote attacker to cause a Denial of Service (DoS) by providing a specially crafted image, leading to system instability or unavailability.
Mitigation: Mitigation for this issue is either not available or the currently available
Debian
CVE-2026-32636: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
vendor_debian·2026·CVSS 5.3
CVE-2026-32636 [MEDIUM] CVE-2026-32636: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-17 and 6.9.13-42, the NewXMLTree method contains a bug that could result in a crash due to an out of write bounds of a single zero byte. Versions 7.1.2-17 and 6.9.13-42 fix the issue.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 8:7.1.2.18+dfsg1-1)
sid: resolved (fixed in 8:7.1.2.18+dfsg1-1)
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-32636 ImageMagick: ImageMagick: Denial of Service via out-of-bounds write in NewXMLTree method
bugzilla·2026-03-18·CVSS 7.5
CVE-2026-32636 [HIGH] CVE-2026-32636 ImageMagick: ImageMagick: Denial of Service via out-of-bounds write in NewXMLTree method
CVE-2026-32636 ImageMagick: ImageMagick: Denial of Service via out-of-bounds write in NewXMLTree method
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-17 and 6.9.13-42, the NewXMLTree method contains a bug that could result in a crash due to an out of write bounds of a single zero byte. Versions 7.1.2-17 and 6.9.13-42 fix the issue.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7 Extended Lifecycle Support
Via RHSA-2026:17618 https://access.redhat.com/errata/RHSA-2026:17618
Wiz
CVE-2025-69204 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2025-69204 [MEDIUM] CVE-2025-69204 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-69204 :
ImageMagick vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, in the WriteSVGImage function, using an int variable to store number_attributes caused an integer overflow. This, in turn, triggered a buffer overflow and caused a DoS attack. Version 7.1.2-12 fixes the issue.
Source : NVD
## 7.5
Score
Published December 30, 2025
Severity HIGH
CNA Score 5.3
Affected Technologies
ImageMagick
Linux Red Hat
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 28.1
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
ImageMagick-c++
ImageMagick-perl
S
Wiz
CVE-2026-32636 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-32636 [MEDIUM] CVE-2026-32636 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32636 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-17 and 6.9.13-42, the NewXMLTree method contains a bug that could result in a crash due to an out of write bounds of a single zero byte. Versions 7.1.2-17 and 6.9.13-42 fix the issue.
Source : NVD
## 7.5
Score
Published March 18, 2026
Severity HIGH
CNA Score 5.3
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Magick.NET-Q16-OpenMP-x64
seal-ImageMagick
Sources
Alpine 3.23 Severity HIGH Has Fix Added at: M
Wiz
CVE-2026-32259 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.7
CVE-2026-32259 [MEDIUM] CVE-2026-32259 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32259 :
ImageMagick vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9.13-41, when a memory allocation fails in the sixel encoder it would be possible to write past the end of a buffer on the stack. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
Source : NVD
## 6.7
Score
Published March 12, 2026
Severity MEDIUM
CNA Score 6.7
Affected Technologies
ImageMagick
Linux Red Hat
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
ImageMagick-c++-devel
ImageMagick-devel
Sources
Alpine 3.10, 3.1
Wiz
CVE-2026-23876 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.1
CVE-2026-23876 [HIGH] CVE-2026-23876 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23876 :
ImageMagick vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-13 and 6.9.13-38, a heap buffer overflow vulnerability in the XBM image decoder (ReadXBMImage) allows an attacker to write controlled data past the allocated heap buffer when processing a maliciously crafted image file. Any operation that reads or identifies an image can trigger the overflow, making it exploitable via common image upload and processing pipelines. Versions 7.1.2-13 and 6.9.13-38 fix the issue.
Source : NVD
## 9.8
Score
Published January 20, 2026
Severity CRITICAL
CNA Score 8.1
Affected Technologies
ImageMagick
Linux Red Hat
Has Public Exploit Yes
Has CISA KEV Exploit No
CI
2026-03-18
Published