CVE-2026-33535
published 2026-03-26CVE-2026-33535: ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9.13-43, an out-of-bounds write of a…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
3.8th percentile
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9.13-43, an out-of-bounds write of a zero byte exists in the X11 `display` interaction path that could lead to a crash. Versions 7.1.2-18 and 6.9.13-43 patch the issue.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imagemagick | < imagemagick 8:7.1.2.18+dfsg1-1 (forky) | imagemagick 8:7.1.2.18+dfsg1-1 (forky) |
| imagemagick | imagemagick | < 7.1.2-18 | 7.1.2-18 |
| imagemagick | imagemagick | < 6.9.13-43 | 6.9.13-43 |
| imagemagick | imagemagick | >= 0 < 8:7.1.2.18+dfsg1-1 | 8:7.1.2.18+dfsg1-1 |
| imagemagick | imagemagick | >= 7.0.0-0 < 7.1.2-18 | 7.1.2-18 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ImageMagick: ImageMagick: Denial of Service via out-of-bounds write in X11 display interaction path
vendor_redhat·2026-03-26·CVSS 4.0
CVE-2026-33535 [MEDIUM] CWE-787 ImageMagick: ImageMagick: Denial of Service via out-of-bounds write in X11 display interaction path
ImageMagick: ImageMagick: Denial of Service via out-of-bounds write in X11 display interaction path
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9.13-43, an out-of-bounds write of a zero byte exists in the X11 `display` interaction path that could lead to a crash. Versions 7.1.2-18 and 6.9.13-43 patch the issue.
A flaw was found in ImageMagick, a free and open-source software used for editing and manipulating digital images. A local attacker could exploit an out-of-bounds write of a zero byte in the X11 display interaction path. This vulnerability, a type of memory corruption, could lead to a crash of the application, resulting in a Denial of Service (DoS).
Statement: Low impact. This flaw in ImageMagick's X11 dis
Debian
CVE-2026-33535: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
vendor_debian·2026·CVSS 4.0
CVE-2026-33535 [MEDIUM] CVE-2026-33535: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9.13-43, an out-of-bounds write of a zero byte exists in the X11 `display` interaction path that could lead to a crash. Versions 7.1.2-18 and 6.9.13-43 patch the issue.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 8:7.1.2.18+dfsg1-1)
sid: resolved (fixed in 8:7.1.2.18+dfsg1-1)
trixie: open
VulDB
ImageMagick up to 6.9.13-42/7.1.2-17 Image Parser out-of-bounds write (GHSA-mw3m-pqr2-qv7c / Nessus ID 307507)
vuldb·2026-04-20·CVSS 5.5
CVE-2026-33535 [MEDIUM] ImageMagick up to 6.9.13-42/7.1.2-17 Image Parser out-of-bounds write (GHSA-mw3m-pqr2-qv7c / Nessus ID 307507)
A vulnerability described as critical has been identified in ImageMagick up to 6.9.13-42/7.1.2-17. The affected element is an unknown function of the component Image Parser. Executing a manipulation can lead to out-of-bounds write.
This vulnerability is tracked as CVE-2026-33535. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
OSV
CVE-2026-33535: ImageMagick is free and open-source software used for editing and manipulating digital images
osv·2026-03-26·CVSS 5.5
CVE-2026-33535 [MEDIUM] CVE-2026-33535: ImageMagick is free and open-source software used for editing and manipulating digital images
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9.13-43, an out-of-bounds write of a zero byte exists in the X11 `display` interaction path that could lead to a crash. Versions 7.1.2-18 and 6.9.13-43 patch the issue.
GHSA
ImageMagick has an Out-of-Bounds write of a zero byte in its X11 display interaction
ghsa·2026-03-26
CVE-2026-33535 [MEDIUM] CWE-787 ImageMagick has an Out-of-Bounds write of a zero byte in its X11 display interaction
ImageMagick has an Out-of-Bounds write of a zero byte in its X11 display interaction
An out-of-bounds write of a zero byte exists in the X11 `display` interaction path that could lead to a crash.
OSV
ImageMagick has an Out-of-Bounds write of a zero byte in its X11 display interaction
osv·2026-03-26
CVE-2026-33535 [MEDIUM] ImageMagick has an Out-of-Bounds write of a zero byte in its X11 display interaction
ImageMagick has an Out-of-Bounds write of a zero byte in its X11 display interaction
An out-of-bounds write of a zero byte exists in the X11 `display` interaction path that could lead to a crash.
No detection rules found.
No public exploits indexed.
Wiz
GHSA-wfx3-6g53-9fgc Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
[MEDIUM] GHSA-wfx3-6g53-9fgc Impact, Exploitability, and Mitigation Steps | Wiz
## GHSA-wfx3-6g53-9fgc :
C# vulnerability analysis and mitigation
A memory leak vulnerability exists in multiple coders that write raw pixel data where an object is not freed.
Direct leak of 160 byte(s) in 1 object(s) allocated from:
Source : NVD
## 3.7
Score
Published February 25, 2026
Severity LOW
CNA Score N/A
Affected Technologies
C#
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Magick.NET-Q16-HDRI-x86
Magick.NET-Q16-OpenMP-arm64
Sources
NVD
NuGet Severity LOW Has Fix Added at: Mar 02, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploit
Wiz
CVE-2026-24687 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.0
CVE-2026-24687 [MEDIUM] CVE-2026-24687 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24687 :
C# vulnerability analysis and mitigation
../
..\
fileName
/umbraco/forms/api/v1/export
Source : NVD
## 6
Score
Published January 29, 2026
Severity MEDIUM
CNA Score 6.0
Affected Technologies
C#
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Umbraco.Forms
Sources
NVD
NuGet Severity MEDIUM Has Fix Added at: Jan 30, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related C# vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
Wiz
CVE-2026-24837 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.6
CVE-2026-24837 [HIGH] CVE-2026-24837 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24837 :
C# vulnerability analysis and mitigation
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 9.0.0 and prior to versions 9.13.10 and 10.2.0, a module friendly name could include scripts that will run during some module operations in the Persona Bar. Versions 9.13.10 and 10.2.0 contain a fix for the issue.
Source : NVD
## 5.4
Score
Published January 28, 2026
Severity MEDIUM
CNA Score 7.6
Affected Technologies
C#
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
DotNetNuke.Core
Sources
NVD
NuGet Severity HIGH Has Fix
Wiz
CVE-2026-28494 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.1
CVE-2026-28494 [HIGH] CVE-2026-28494 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28494 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a stack buffer overflow exists in ImageMagick's morphology kernel parsing functions. User-controlled kernel strings exceeding a buffer are copied into fixed-size stack buffers via memcpy without bounds checking, resulting in stack corruption. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
Source : NVD
## 7.1
Score
Published March 10, 2026
Severity HIGH
CNA Score 7.1
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.6
Exploitation Probability (EP
Wiz
CVE-2026-25799 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-25799 [MEDIUM] CVE-2026-25799 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25799 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a logic error in YUV sampling factor validation allows an invalid sampling factor to bypass checks and trigger a division-by-zero during image loading, resulting in a reliable denial-of-service. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
Source : NVD
## 7.5
Score
Published February 24, 2026
Severity HIGH
CNA Score 5.3
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
ImageMagi
Wiz
CVE-2026-30931 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.8
CVE-2026-30931 [MEDIUM] CVE-2026-30931 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-30931 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, a heap-based buffer overflow in the UHDR encoder can happen due to truncation of a value and it would allow an out of bounds write. This vulnerability is fixed in 7.1.2-16.
Source : NVD
## 7.8
Score
Published March 10, 2026
Severity HIGH
CNA Score 6.8
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
imagemagick
Magick.NET-Q16-HDRI-arm64
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16,
Wiz
CVE-2025-67291 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.1
CVE-2025-67291 [MEDIUM] CVE-2025-67291 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-67291 :
C# vulnerability analysis and mitigation
A stored cross-site scripting (XSS) vulnerability in the Media module of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name field.
Source : NVD
## 6.1
Score
Published December 22, 2025
Severity MEDIUM
CNA Score 6.1
Affected Technologies
C#
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 15.7
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
Piranha
Sources
NVD
NuGet Severity LOW No Fix Added at: Dec 23, 2025
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not jus
Wiz
CVE-2026-23874 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-23874 [MEDIUM] CVE-2026-23874 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23874 :
C# vulnerability analysis and mitigation
Source : NVD
## 5.5
Score
Published January 20, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
C#
ImageMagick
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Magick.NET-Q8-OpenMP-x64
Magick.NET-Q16-HDRI-arm64
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21, 3.22, 3.23, edge Severity MEDIUM No Fix Added at: Jan 29, 2026
Chainguard Has Fix Added at: Jan 21, 2026
Debian 11, 12, 13, 14 Severity MEDIUM Has Fix Added at: Jan 21, 2026
Echo Severity MEDIUM Has Fix Added at: Jan 21, 2026
NuGet Severity MED
Wiz
GHSA-xpg8-7m6m-jf56 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
[MEDIUM] GHSA-xpg8-7m6m-jf56 Impact, Exploitability, and Mitigation Steps | Wiz
## GHSA-xpg8-7m6m-jf56 :
C# vulnerability analysis and mitigation
An attacker can inject arbitrary MVG (Magick Vector Graphics) drawing commands in an SVG file that is read by the internal SVG decoder of ImageMagick. The injected MVG commands execute during rendering.
Source : NVD
Published February 25, 2026
Severity LOW
CNA Score N/A
Affected Technologies
C#
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Magick.NET-Q8-OpenMP-arm64
Magick.NET-Q8-OpenMP-x64
Sources
NVD
NuGet Severity LOW Has Fix Added at: Mar 02, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus
Wiz
CVE-2026-25543 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.3
CVE-2026-25543 [MEDIUM] CVE-2026-25543 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25543 :
C# vulnerability analysis and mitigation
HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. Prior to versions 9.0.892 and 9.1.893-beta, if the template tag is allowed, its contents are not sanitized. The template tag is a special tag that does not usually render its contents, unless the shadowrootmode attribute is set to open or closed. This issue has been patched in versions 9.0.892 and 9.1.893-beta.
Source : NVD
## 6.3
Score
Published February 4, 2026
Severity MEDIUM
CNA Score 6.3
Affected Technologies
C#
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.8
Exploitation Probability (EPSS) N/A
Af
Wiz
CVE-2026-26130 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-26130 [HIGH] CVE-2026-26130 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-26130 :
C# vulnerability analysis and mitigation
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Source : NVD
## 7.5
Score
Published March 10, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
C#
ASP.NET Core
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 72
Exploitation Probability (EPSS) 0.7
Affected packages and libraries
dotnet-runtime-9.0-debuginfo
dotnet-sdk-9.0-source-built-artifacts
Sources
AlmaLinux 8 Severity HIGH Has Fix Added at: Mar 13, 2026
AlmaLinux 9 Severity HIGH Has Fix Added at: Mar 13, 2026
Alpine 3.20, 3.21, 3.22, 3.23 Severity HIGH Has Fix Added at: Mar
Wiz
CVE-2026-31853 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.7
CVE-2026-31853 [MEDIUM] CVE-2026-31853 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-31853 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9.13-41, an overflow on 32-bit systems can cause a crash in the SFW decoder when processing extremely large images. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
Source : NVD
## 5.5
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.7
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libMagickWand-7_Q16HDRI10
ImageMagick-devel
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.1
Wiz
CVE-2026-28493 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-28493 [MEDIUM] CVE-2026-28493 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28493 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, an integer overflow vulnerability exists in the SIXEL decoer. The vulnerability allows an attacker to perform an out of bounds via a specially crafted image. This vulnerability is fixed in 7.1.2-16.
Source : NVD
## 6.5
Score
Published March 10, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 17.3
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
Magick.NET-Q16-HDRI-OpenMP-arm64
Magick.NET-Q16-HDRI-arm64
Sources
Wiz
CVE-2026-26066 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.2
CVE-2026-26066 [MEDIUM] CVE-2026-26066 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-26066 :
C# vulnerability analysis and mitigation
IPTCTEXT
Source : NVD
## 7.5
Score
Published February 24, 2026
Severity HIGH
CNA Score 6.2
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
ImageMagick-config-7-upstream-secure
ImageMagick-libs
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21, 3.22, 3.23, edge Severity HIGH Has Fix Added at: Mar 02, 2026
Chainguard Has Fix Added at: Feb 24, 2026
Debian 11, 12, 13, 14 Severity HIGH Has Fix Added at: Feb 24, 2026
Echo Severity HIGH Has Fix Added at: Feb 24, 2026
NuGet Severi
Wiz
GHSA-p6q4-fgr8-vx4p Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
[MEDIUM] GHSA-p6q4-fgr8-vx4p Impact, Exploitability, and Mitigation Steps | Wiz
## GHSA-p6q4-fgr8-vx4p :
C# vulnerability analysis and mitigation
## Summary
StackOverflowException via nested array initializers bypasses ExpressionDepthLimit fix (GHSA-wgh7-7m3c-fx25)
## Details
ExpressionDepthLimit
[[[[...
ParseArrayInitializer
ParseExpression
ParseArrayInitializer
StackOverflowException
## PoC
using Scriban;
// ExpressionDepthLimit (default 250) does NOT prevent this crash
string nested = "{{ " + new string('[', 5000) + "1" + new string(']', 5000) + " }}";
Template.Parse(nested); // StackOverflowException - process terminates
## Impact
Same as GHSA-wgh7-7m3c-fx25: High severity. StackOverflowException cannot be caught with try/catch in .NET - the process terminates immediately. Any application calling Template.Parse with untrusted input is vulnerab
Wiz
CVE-2026-25965 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.6
CVE-2026-25965 [HIGH] CVE-2026-25965 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25965 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick’s path security policy is enforced on the raw filename string before the filesystem resolves it. As a result, a policy rule such as /etc/* can be bypassed by a path traversal. The OS resolves the traversal and opens the sensitive file, but the policy matcher only sees the unnormalized path and therefore allows the read. This enables local file disclosure (LFI) even when policy-secure.xml is applied. Actions to prevent reading from files have been taken in versions .7.1.2-15 and 6.9.13-40 But it make sure writing is also not possible the following should be added to one's policy. Th
Wiz
CVE-2026-25986 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-25986 [MEDIUM] CVE-2026-25986 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25986 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer overflow write vulnerability exists in ReadYUVImage() (coders/yuv.c) when processing malicious YUV 4:2:2 (NoInterlace) images. The pixel-pair loop writes one pixel beyond the allocated row buffer. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
Source : NVD
## 9.8
Score
Published February 24, 2026
Severity CRITICAL
CNA Score 5.3
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.2
Exploitation Probability (EPSS) N/A
Affected packages and
Wiz
CVE-2026-32933 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-32933 [HIGH] CVE-2026-32933 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32933 :
C# vulnerability analysis and mitigation
StackOverflowException
Source : NVD
## 7.5
Score
Published March 20, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
C#
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 17.1
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
AutoMapper
Sources
NVD
NuGet Severity HIGH Has Fix Added at: Mar 17, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related C# vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
GHSA-mvm6-f9r3-fgfx
HIGH
7.7
Wiz
CVE-2026-25797 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.7
CVE-2026-25797 [MEDIUM] CVE-2026-25797 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25797 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the ps coders, responsible for writing PostScript files, fails to sanitize the input before writing it into the PostScript header. An attacker can provide a malicous file and inject arbitrary PostScript code. When the resulting file is processed by a printer or a viewer (like Ghostscript), the injected code is interpreted and executed. The html encoder does not properly escape strings that are written to in the html document. An attacker can provide a malicious file and injection arbitrary html code. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
Source : NVD
## 5.3
Score
Published Feb
Wiz
CVE-2026-25796 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-25796 [MEDIUM] CVE-2026-25796 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25796 :
C# vulnerability analysis and mitigation
ReadSTEGANOImage()
coders/stegano.c
watermark
Source : NVD
## 7.5
Score
Published February 24, 2026
Severity HIGH
CNA Score 5.3
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Magick.NET-Q16-HDRI-arm64
Magick.NET-Q16-HDRI-x64
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21, 3.22, 3.23, edge Severity HIGH Has Fix Added at: Mar 02, 2026
Chainguard Has Fix Added at: Feb 24, 2026
Debian 11, 12, 13, 14 Severity HIGH Has Fix Added at: Feb 24, 2026
Echo Severity HIGH Has Fix Add
Wiz
GHSA-6p22-q7w5-33pg Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
[MEDIUM] GHSA-6p22-q7w5-33pg Impact, Exploitability, and Mitigation Steps | Wiz
## GHSA-6p22-q7w5-33pg :
C# vulnerability analysis and mitigation
The ASHLAR coder leaks a temporary image when an action fails and that could result to an out of memory.
Source : NVD
## 3.3
Score
Published March 26, 2026
Severity LOW
CNA Score N/A
Affected Technologies
C#
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Magick.NET-Q8-arm64
Magick.NET-Q16-HDRI-AnyCPU
Sources
NVD
NuGet Severity LOW Has Fix Added at: Mar 29, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related C# vulnerabilities:
CVE ID
Wiz
GHSA-xw6w-9jjh-p9cr Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
GHSA-xw6w-9jjh-p9cr Impact, Exploitability, and Mitigation Steps | Wiz
## GHSA-xw6w-9jjh-p9cr :
C# vulnerability analysis and mitigation
## Summary
LimitToString
LoopLimit
## Details
## Vector 1: Unbounded string multiplication
ScriptBinaryExpression.cs
CalculateToString
string * int
// src/Scriban/Syntax/Expressions/ScriptBinaryExpression.cs:319-334
var leftText = context.ObjectToString(left);
var builder = new StringBuilder();
for (int i = 0; i
// src/Scriban/Syntax/Expressions/ScriptBinaryExpression.cs:401-417
private static IEnumerable RangeInclude(BigInteger left, BigInteger right)
{
if (left ().Count()
ArrayFunctions.Join
foreach
StringBuilder
## PoC
## Vector 1 — String multiplication OOM:
var template = Template.Parse("{{ 'AAAA' * 500000000 }}");
var context = new TemplateContext();
// context.LimitToString is 1048576 by defaul
Wiz
CVE-2026-30227 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.9
CVE-2026-30227 [MEDIUM] CVE-2026-30227 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-30227 :
C# vulnerability analysis and mitigation
MimeKit is a C# library which may be used for the creation and parsing of messages using the Multipurpose Internet Mail Extension (MIME), as defined by numerous IETF specifications. Prior to version 4.15.1, a CRLF injection vulnerability in MimeKit allows an attacker to embed \r\n into the SMTP envelope address local-part (when the local-part is a quoted-string). This is non-compliant with RFC 5321 and can result in SMTP command injection (e.g., injecting additional RCPT TO / DATA / RSET commands) and/or mail header injection, depending on how the application uses MailKit/MimeKit to construct and send messages. The issue becomes exploitable when the attacker can influence a MailboxAddress (MAIL FROM / RCPT TO) value that is lat
Wiz
CVE-2025-65581 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2025-65581 [MEDIUM] CVE-2025-65581 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-65581 :
C# vulnerability analysis and mitigation
An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improper validation of the returnUrl parameter in the register function allows an attacker to redirect users to arbitrary external domains.
Source : NVD
## 5.3
Score
Published December 16, 2025
Severity MEDIUM
CNA Score 5.3
Affected Technologies
C#
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 18.6
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
Volo.Abp.Account.Web
Sources
NVD
NuGet Severity MEDIUM Has Fix Added at: Dec 17, 2025
## Get a CVE risk assessment
Get a prioritized view o
Wiz
CVE-2026-25971 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.2
CVE-2026-25971 [MEDIUM] CVE-2026-25971 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25971 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, Magick fails to check for circular references between two MSLs, leading to a stack overflow. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
Source : NVD
## 9.8
Score
Published February 24, 2026
Severity CRITICAL
CNA Score 6.2
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 13
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Magick.NET-Q8-OpenMP-x64
Magick.NET-Q8-arm64
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.1
Wiz
CVE-2025-69204 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2025-69204 [MEDIUM] CVE-2025-69204 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-69204 :
ImageMagick vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, in the WriteSVGImage function, using an int variable to store number_attributes caused an integer overflow. This, in turn, triggered a buffer overflow and caused a DoS attack. Version 7.1.2-12 fixes the issue.
Source : NVD
## 7.5
Score
Published December 30, 2025
Severity HIGH
CNA Score 5.3
Affected Technologies
ImageMagick
Linux Red Hat
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 28.1
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
ImageMagick-c++
ImageMagick-perl
S
Wiz
CVE-2026-28686 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.8
CVE-2026-28686 [MEDIUM] CVE-2026-28686 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28686 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, A heap-buffer-overflow vulnerability exists in the PCL encode due to an undersized output buffer allocation. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
Source : NVD
## 6.8
Score
Published March 10, 2026
Severity MEDIUM
CNA Score 6.8
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Magick.NET-Q16-HDRI-OpenMP-x64
Magick.NET-Q16-arm64
Sources
Alpine 3.10, 3.11, 3.12, 3.
Wiz
CVE-2026-26127 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-26127 [HIGH] CVE-2026-26127 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-26127 :
C# vulnerability analysis and mitigation
Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network.
Source : NVD
## 7.5
Score
Published March 10, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
C#
.NET SDK
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 28.3
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
Microsoft.Bcl.Memory
dotnet-apphost-pack-9.0
Sources
AlmaLinux 8 Severity HIGH Has Fix Added at: Mar 13, 2026
AlmaLinux 9 Severity HIGH Has Fix Added at: Mar 17, 2026
Alpine 3.21, 3.22, 3.23 Severity HIGH Has Fix Added at: Mar 13, 2026
Alpine edge Severity HIGH Has Fix Added at: Mar 14, 2026
Chai
Wiz
CVE-2026-28690 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.9
CVE-2026-28690 [MEDIUM] CVE-2026-28690 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28690 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a stack buffer overflow vulnerability exists in the MNG encoder. There is a bounds checks missing that could corrupting the stack with attacker-controlled data. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
Source : NVD
## 6.5
Score
Published March 10, 2026
Severity MEDIUM
CNA Score 6.9
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Magick.NET-Q16-OpenMP-x86
Magick.NET-
Wiz
GHSA-xcx6-vp38-8hr5 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
GHSA-xcx6-vp38-8hr5 Impact, Exploitability, and Mitigation Steps | Wiz
## GHSA-xcx6-vp38-8hr5 :
C# vulnerability analysis and mitigation
## Summary
object.to_json
WriteValue()
object.to_json
StackOverflowException
StackOverflowException
## Details
WriteValue()
src/Scriban/Functions/ObjectFunctions.cs:494
static void WriteValue(TemplateContext context, Utf8JsonWriter writer, object value)
{
var type = value?.GetType() ?? typeof(object);
if (value is null || value is string || value is bool ||
type.IsPrimitiveOrDecimal() || value is IFormattable)
{
JsonSerializer.Serialize(writer, value, type);
}
else if (value is IList || type.IsArray) {
writer.WriteStartArray();
foreach (var x in context.ToList(context.CurrentSpan, value))
{
WriteValue(context, writer, x); // recursive, no depth check
}
writer.WriteEndArray();
}
else {
writer.WriteStartObject();
Wiz
CVE-2026-26284 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-26284 [MEDIUM] CVE-2026-26284 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-26284 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick lacks proper boundary checking when processing Huffman-coded data from PCD (Photo CD) files. The decoder contains an function that has an incorrect initialization that could cause an out of bounds read. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
Source : NVD
## 9.1
Score
Published February 24, 2026
Severity CRITICAL
CNA Score 6.5
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.9
Exploitation Probability (EPSS) N/A
Affected packages
Wiz
CVE-2026-27799 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
CVE-2026-27799 [MEDIUM] CVE-2026-27799 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27799 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in the DJVU image format handler. The vulnerability occurs due to integer truncation when calculating the stride (row size) for pixel buffer allocation. The stride calculation overflows a 32-bit signed integer, resulting in an out-of-bounds memory reads. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
Source : NVD
## 4.4
Score
Published February 26, 2026
Severity MEDIUM
CNA Score 4.0
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probabi
Wiz
CVE-2026-25638 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-25638 [MEDIUM] CVE-2026-25638 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25638 :
C# vulnerability analysis and mitigation
coders/msl.c
WriteMSLImage
msl.c
Source : NVD
## 5.3
Score
Published February 24, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
ImageMagick-perl-debuginfo
libMagick++-7_Q16HDRI5-32bit
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21, 3.22, 3.23, edge Severity MEDIUM Has Fix Added at: Feb 24, 2026
Chainguard Has Fix Added at: Feb 24, 2026
Debian 11, 12, 13, 14 Severity MEDIUM Has Fix Added at: Feb 24, 2026
Echo Severity MEDIUM Has Fix Ad
Wiz
GHSA-v66j-x4hw-fv9g Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
GHSA-v66j-x4hw-fv9g Impact, Exploitability, and Mitigation Steps | Wiz
## GHSA-v66j-x4hw-fv9g :
C# vulnerability analysis and mitigation
## Summary
string.pad_left
string.pad_right
width
OutOfMemoryException
## Details
StringFunctions.PadLeft
StringFunctions.PadRight
src/Scriban/Functions/StringFunctions.cs:1181-1203
String.PadLeft(int)
String.PadRight(int)
// src/Scriban/Functions/StringFunctions.cs:1181-1183
public static string PadLeft(string text, int width)
{
return (text ?? string.Empty).PadLeft(width);
}
// src/Scriban/Functions/StringFunctions.cs:1200-1202
public static string PadRight(string text, int width)
{
return (text ?? string.Empty).PadRight(width);
}
TemplateContext.LimitToString
TemplateContext.cs:147
ObjectToString()
TemplateContext.Helpers.cs:101-103
PadLeft
PadRight
src/Scriban.AppService/Program.cs:63-140
POST /ap
Wiz
GHSA-wgh7-7m3c-fx25 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
[MEDIUM] GHSA-wgh7-7m3c-fx25 Impact, Exploitability, and Mitigation Steps | Wiz
## GHSA-wgh7-7m3c-fx25 :
C# vulnerability analysis and mitigation
StackOverflowException
StackOverflowException
try-catch
ExpressionDepthLimit
ParserOptions
null
## Impact
StackOverflowException
## Proof of Concept (PoC)
The following C# code demonstrates the vulnerability. Executing this code will immediately terminate the application process.
using Scriban;
// Creates a deeply nested expression: (((( ... (1) ... ))))
string nested = new string('(', 10000) + "1" + new string(')', 10000);
try {
// This will crash the entire process immediately
Scriban.Template.Parse("{{ " + nested + " }}");
} catch (Exception ex) {
// This catch block will never execute because StackOverflowException
Console.WriteLine("Caught exception: " + ex.Message);
}
## Suggested Remediation
Parser
Wiz
CVE-2026-25966 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.9
CVE-2026-25966 [MEDIUM] CVE-2026-25966 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25966 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. The shipped "secure" security policy includes a rule intended to prevent reading/writing from standard streams. However, ImageMagick also supports fd: pseudo-filenames (e.g., fd:0, fd:1). Prior to versions 7.1.2-15 and 6.9.13-40, this path form is not blocked by the secure policy templates, and therefore bypasses the protection goal of "no stdin/stdout." Versions 7.1.2-15 and 6.9.13-40 contain a patch by including a change to the more secure policies by default. As a workaround, add the change to one's security policy manually.
Source : NVD
## 7.8
Score
Published February 24, 2026
Severity HIGH
CNA Score 5.9
Affected Technolo
Wiz
CVE-2026-24784 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.8
CVE-2026-24784 [MEDIUM] CVE-2026-24784 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24784 :
C# vulnerability analysis and mitigation
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 9.0.0 and prior to versions 9.13.10 and 10.2.0, a content editor could inject scripts in module headers/footers that would run for other users. Versions 9.13.10 and 10.2.0 contain a fix for the issue.
Source : NVD
## 4.8
Score
Published January 28, 2026
Severity MEDIUM
CNA Score 6.8
Affected Technologies
C#
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
DotNetNuke.Core
Sources
NVD
NuGet Severity MEDIUM Has Fix Added at:
Wiz
CVE-2025-66631 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.2
CVE-2025-66631 [HIGH] CVE-2025-66631 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-66631 :
C# vulnerability analysis and mitigation
CSLA .NET is a framework designed for the development of reusable, object-oriented business layers for applications. Versions 5.5.4 and below allow the use of WcfProxy. WcfProxy uses the now-obsolete NetDataContractSerializer (NDCS) and is vulnerable to remote code execution during deserialization. This vulnerability is fixed in version 6.0.0. To workaround this issue, remove the WcfProxy in data portal configurations.
Source : NVD
## 7.2
Score
Published December 9, 2025
Severity HIGH
CNA Score 7.2
Affected Technologies
C#
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 77.3
Exploitation Probability (EPSS) 1
Affected packag
Wiz
CVE-2026-25637 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-25637 [MEDIUM] CVE-2026-25637 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25637 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-15, a memory leak in the ASHLAR image writer allows an attacker to exhaust process memory by providing a crafted image that results in small objects that are allocated but never freed. Version 7.1.2-15 contains a patch.
Source : NVD
## 5.3
Score
Published February 24, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 17.4
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
ImageMagick-config-7-upstream
ImageMagick-config
Wiz
GHSA-wgxp-q8xq-wpp9 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
[MEDIUM] GHSA-wgxp-q8xq-wpp9 Impact, Exploitability, and Mitigation Steps | Wiz
## GHSA-wgxp-q8xq-wpp9 :
C# vulnerability analysis and mitigation
The PCD coder’s DecodeImage loop allows a crafted PCD file to trigger a 1‑byte heap out-of-bounds read when decoding an image (Denial of service) and potential disclosure of adjacent heap byte.
Source : NVD
## 3.7
Score
Published February 25, 2026
Severity LOW
CNA Score N/A
Affected Technologies
C#
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Magick.NET-Q8-AnyCPU
Magick.NET-Q8-x86
Sources
NVD
NuGet Severity LOW Has Fix Added at: Mar 02, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on wh
Wiz
CVE-2026-28689 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.3
CVE-2026-28689 [MEDIUM] CVE-2026-28689 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28689 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, domain="path" authorization is checked before final file open/use. A symlink swap between check-time and use-time bypasses policy-denied read/write. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
Source : NVD
## 6.3
Score
Published March 10, 2026
Severity MEDIUM
CNA Score 6.3
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libMagick++-devel
ImageMagick-c++
Sources
Alpin
Wiz
CVE-2026-28688 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
CVE-2026-28688 [MEDIUM] CVE-2026-28688 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28688 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a heap-use-after-free vulnerability exists in the MSL encoder, where a cloned image is destroyed twice. The MSL coder does not support writing MSL so the write capability has been removed. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
Source : NVD
## 5.3
Score
Published March 10, 2026
Severity MEDIUM
CNA Score 4.0
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
imagemagi
Wiz
CVE-2026-30937 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.8
CVE-2026-30937 [MEDIUM] CVE-2026-30937 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-30937 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a 32-bit unsigned integer overflow in the XWD (X Windows) encoder can cause an undersized heap buffer allocation. When writing a extremely large image an out of bounds heap write can occur. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
Source : NVD
## 6.1
Score
Published March 10, 2026
Severity MEDIUM
CNA Score 6.8
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
ImageMagi
Wiz
GHSA-3q5f-gmjc-38r8 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
[MEDIUM] GHSA-3q5f-gmjc-38r8 Impact, Exploitability, and Mitigation Steps | Wiz
## GHSA-3q5f-gmjc-38r8 :
C# vulnerability analysis and mitigation
texture
texture=ReadImage(read_info,exception);
GetTypeMetrics
status == MagickFalse
Source : NVD
Published February 25, 2026
Severity LOW
CNA Score N/A
Affected Technologies
C#
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Magick.NET-Q8-arm64
Magick.NET-Q8-x86
Sources
NVD
NuGet Severity LOW Has Fix Added at: Mar 02, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related C# vulnerabilities:
CVE ID
Severity
Score
Technologies
Componen
Wiz
CVE-2025-66625 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.9
CVE-2025-66625 [MEDIUM] CVE-2025-66625 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-66625 :
C# vulnerability analysis and mitigation
Umbraco is an ASP.NET CMS. Due to unsafe handling and deletion of temporary files in versions 10.0.0 through 13.12.0, during the dictionary upload process an attacker with access to the backoffice can trigger predictable requests to temporary file paths. The application’s error responses (HTTP 500 when a file exists, 404 when it does not) allow the attacker to enumerate the existence of arbitrary files on the server’s filesystem. This vulnerability does not allow reading or writing file contents. In certain configurations, incomplete clean-up of temporary upload files may additionally expose the NTLM hash of the Windows account running the Umbraco application. This issue is fixed in version 13.12.1.
Source : NVD
## 4.9
Sco
Wiz
CVE-2026-31833 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.7
CVE-2026-31833 [MEDIUM] CVE-2026-31833 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-31833 :
C# vulnerability analysis and mitigation
Umbraco is an ASP.NET CMS. From 16.2.0 to before 16.5.1 and 17.2.2, An authenticated backoffice user with access to Settings can inject malicious HTML into property type descriptions. Due to an overly permissive attributeNameCheck configuration (/.+/) in the UFM DOMPurify instance, event handler attributes such as onclick and onload, when used within Umbraco web components (umb- , uui- , ufm-*) were not filtered. This vulnerability is fixed in 16.5.1 and 17.2.2.
Source : NVD
## 6.7
Score
Published March 10, 2026
Severity MEDIUM
CNA Score 6.7
Affected Technologies
C#
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 18.1
Exploi
Wiz
CVE-2026-30935 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.4
CVE-2026-30935 [MEDIUM] CVE-2026-30935 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-30935 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, BilateralBlurImage contains a heap buffer over-read caused by an incorrect conversion. When processing a crafted image with the -bilateral-blur operation an out of bounds read can occur. This vulnerability is fixed in 7.1.2-16.
Source : NVD
## 4.4
Score
Published March 10, 2026
Severity MEDIUM
CNA Score 4.4
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
perl-PerlMagick
Magick.NET-Q16-AnyCPU
Wiz
CVE-2026-28687 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-28687 [MEDIUM] CVE-2026-28687 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28687 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a heap use-after-free vulnerability in ImageMagick's MSL decoder allows an attacker to trigger access to freed memory by crafting an MSL file. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
Source : NVD
## 5.3
Score
Published March 10, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 16.9
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
Magick.NET-Q16-OpenMP-arm64
ImageMagick-config-7-upstr
Wiz
GHSA-grr9-747v-xvcp Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
[MEDIUM] GHSA-grr9-747v-xvcp Impact, Exploitability, and Mitigation Steps | Wiz
## GHSA-grr9-747v-xvcp :
C# vulnerability analysis and mitigation
ObjectRecursionLimit
StackOverflowException
{{ obj }}
TemplateContext
ObjectRecursionLimit
0
## Proof of Concept (PoC)
StackOverflowException
using Scriban;
using Scriban.Runtime;
var template = Template.Parse("{{ a }}");
var context = new TemplateContext();
var a = new ScriptObject();
// Introduce a cycle
a["self"] = a;
context.PushGlobal(new ScriptObject { { "a", a } });
try {
// This crashes the entire process immediately
template.Render(context);
} catch (Exception ex) {
// This will never execute because StackOverflowException
Console.WriteLine("Caught exception: " + ex.Message);
}
## Impact
This vulnerability allows a Denial of Service (DoS) attack. If a malicious user can manipulate the data structure
Wiz
GHSA-3j4x-rwrx-xxj9 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
[MEDIUM] GHSA-3j4x-rwrx-xxj9 Impact, Exploitability, and Mitigation Steps | Wiz
## GHSA-3j4x-rwrx-xxj9 :
C# vulnerability analysis and mitigation
A use-after-free vulnerability exists in the PDB decoder that will use a stale pointer when a memory allocation fails and that could result in a crash or a single zero byte write.
==4033155==ERROR: AddressSanitizer: UNKNOWN SIGNAL on unknown address 0x000000000000 (pc 0x5589c1971b24 bp 0x7ffdcc7ae2d0 sp 0x7ffdcc7adb20 T0)
==4034812==ERROR: AddressSanitizer: heap-use-after-free on address 0x7f099e9f7800 at pc 0x5605d909ab20 bp 0x7ffe52045b50 sp 0x7ffe52045b40
WRITE of size 1 at 0x7f099e9f7800 thread T0
Source : NVD
## 3.7
Score
Published February 25, 2026
Severity LOW
CNA Score N/A
Affected Technologies
C#
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploita
Wiz
CVE-2026-25983 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-25983 [MEDIUM] CVE-2026-25983 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25983 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted MSL script triggers a heap-use-after-free. The operation element handler replaces and frees the image while the parser continues reading from it, leading to a UAF in ReadBlobString during further parsing. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
Source : NVD
## 9.8
Score
Published February 24, 2026
Severity CRITICAL
CNA Score 5.3
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.1
Exploitation Probability (EPSS) N/A
Affected packages
Wiz
CVE-2026-25985 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-25985 [HIGH] CVE-2026-25985 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25985 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted SVG file containing an malicious element causes ImageMagick to attempt to allocate ~674 GB of memory, leading to an out-of-memory abort. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
Source : NVD
## 7.5
Score
Published February 24, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Magick.NET-Q16-OpenMP-x64
Magick.NET-Q16-OpenMP-x86
Sou
Wiz
GHSA-gq5v-qf8q-fp77 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
[MEDIUM] GHSA-gq5v-qf8q-fp77 Impact, Exploitability, and Mitigation Steps | Wiz
## GHSA-gq5v-qf8q-fp77 :
C# vulnerability analysis and mitigation
OpenPixelCache
GetPixelIndex
Source : NVD
## 3.3
Score
Published February 25, 2026
Severity LOW
CNA Score N/A
Affected Technologies
C#
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Magick.NET-Q16-x86
Magick.NET-Q8-OpenMP-x64
Sources
NVD
NuGet Severity LOW Has Fix Added at: Mar 02, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related C# vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Wiz
CVE-2026-32636 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-32636 [MEDIUM] CVE-2026-32636 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32636 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-17 and 6.9.13-42, the NewXMLTree method contains a bug that could result in a crash due to an out of write bounds of a single zero byte. Versions 7.1.2-17 and 6.9.13-42 fix the issue.
Source : NVD
## 7.5
Score
Published March 18, 2026
Severity HIGH
CNA Score 5.3
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Magick.NET-Q16-OpenMP-x64
seal-ImageMagick
Sources
Alpine 3.23 Severity HIGH Has Fix Added at: M
Wiz
CVE-2026-25982 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-25982 [MEDIUM] CVE-2026-25982 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25982 :
C# vulnerability analysis and mitigation
coders/dcm.c
Source : NVD
## 6.5
Score
Published February 24, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
ImageMagick-config-7-upstream-secure
ImageMagick-devel
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21, 3.22, 3.23, edge Severity MEDIUM Has Fix Added at: Mar 02, 2026
Chainguard Has Fix Added at: Feb 24, 2026
Debian 11, 12, 13, 14 Severity MEDIUM Has Fix Added at: Feb 24, 2026
Echo Severity MEDIUM Has Fix Added at: Feb 24, 2026
Wiz
GHSA-9r56-3gjq-hqf7 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
[MEDIUM] GHSA-9r56-3gjq-hqf7 Impact, Exploitability, and Mitigation Steps | Wiz
## GHSA-9r56-3gjq-hqf7 :
C# vulnerability analysis and mitigation
APP1JPEG
Source : NVD
## 3.3
Score
Published March 26, 2026
Severity LOW
CNA Score N/A
Affected Technologies
C#
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Magick.NET-Q8-OpenMP-arm64
Magick.NET-Q8-x64
Sources
NVD
NuGet Severity LOW Has Fix Added at: Mar 29, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related C# vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
GHSA-mv
Wiz
CVE-2026-26131 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-26131 [HIGH] CVE-2026-26131 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-26131 :
C# vulnerability analysis and mitigation
Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally.
Source : NVD
## 7.8
Score
Published March 10, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
C#
.NET SDK
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
dotnet-runtime-10.0
dotnet-runtime-dbg-10.0
Sources
Alpine 3.23 Severity HIGH Has Fix Added at: Mar 13, 2026
Alpine edge Severity HIGH Has Fix Added at: Mar 14, 2026
NuGet Severity HIGH Has Fix Added at: Mar 12, 2026
Red Hat 8, 9, 10 Severity MEDIUM No Fix Added at: Mar 12, 2026
Linux Seve
Wiz
CVE-2026-30883 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.7
CVE-2026-30883 [MEDIUM] CVE-2026-30883 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-30883 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an extremely large image profile could result in a heap overflow when encoding a PNG image. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
Source : NVD
## 7.8
Score
Published March 10, 2026
Severity HIGH
CNA Score 5.7
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libGraphicsMagick++-devel
Magick.NET-Q8-AnyCPU
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.
Wiz
CVE-2025-68950 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
CVE-2025-68950 [MEDIUM] CVE-2025-68950 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68950 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, Magick fails to check for circular references between two MVGs, leading to a stack overflow. This is a DoS vulnerability, and any situation that allows reading the mvg file will be affected. Version 7.1.2-12 fixes the issue.
Source : NVD
## 6.2
Score
Published December 30, 2025
Severity MEDIUM
CNA Score 4.0
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
ImageMagick-devel
Magick.NET-Q8-x86
Sou
Wiz
GHSA-2gq3-ww97-wfjm Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
[MEDIUM] GHSA-2gq3-ww97-wfjm Impact, Exploitability, and Mitigation Steps | Wiz
## GHSA-2gq3-ww97-wfjm :
C# vulnerability analysis and mitigation
A heap Use After Free vulnerability exists in the meta coder when an allocation fails and a single byte is written to a stale pointer.
==535852==ERROR: AddressSanitizer: heap-use-after-free on address 0x5210000088ff at pc 0x5581bacac14d bp 0x7ffdf667edf0 sp 0x7ffdf667ede0
WRITE of size 1 at 0x5210000088ff thread T0
Source : NVD
## 3.7
Score
Published February 25, 2026
Severity LOW
CNA Score N/A
Affected Technologies
C#
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Magick.NET-Q16-OpenMP-arm64
Magick.NET-Q8-arm64
Sources
NVD
NuGet Severity LO
Wiz
CVE-2026-30929 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.7
CVE-2026-30929 [HIGH] CVE-2026-30929 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-30929 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, MagnifyImage uses a fixed-size stack buffer. When using a specific image it is possible to overflow this buffer and corrupt the stack. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
Source : NVD
## 7.8
Score
Published March 10, 2026
Severity HIGH
CNA Score 7.7
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
ImageMagick-config-7-upstream-secure
perl-PerlMagick
Sources
Al
Wiz
CVE-2026-26983 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-26983 [MEDIUM] CVE-2026-26983 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-26983 :
C# vulnerability analysis and mitigation
Source : NVD
## 5.3
Score
Published February 24, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
ImageMagick-config-7-upstream-websafe
Magick.NET-Q8-x86
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21, 3.22, 3.23, edge Severity MEDIUM Has Fix Added at: Mar 02, 2026
Chainguard Has Fix Added at: Feb 24, 2026
Debian 11, 12 Severity MEDIUM No Fix Added at: Feb 24, 2026
Debian 13, 14 Severity MEDIUM Has Fix Added at: Feb 24, 2026
Echo Severit
Wiz
CVE-2026-27449 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-27449 [HIGH] CVE-2026-27449 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27449 :
C# vulnerability analysis and mitigation
Umbraco Engage is a business intelligence platform. A vulnerability has been identified in Umbraco Engage prior to versions 16.2.1 and 17.1.1 where certain API endpoints are exposed without enforcing authentication or authorization checks. The affected endpoints can be accessed directly over the network without requiring a valid session or user credentials. By supplying a user-controlled identifier parameter (e.g., ?id=), an attacker can retrieve sensitive data associated with arbitrary records. Because no access control validation is performed, the endpoints are vulnerable to enumeration attacks, allowing attackers to iterate over identifiers and extract data at scale. An unauthenticated attacker can retrieve sensitive Engage-
Wiz
GHSA-5wr9-m6jw-xx44 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
GHSA-5wr9-m6jw-xx44 Impact, Exploitability, and Mitigation Steps | Wiz
## GHSA-5wr9-m6jw-xx44 :
C# vulnerability analysis and mitigation
## Summary
TemplateContext
Type
MemberFilter
MemberRenamer
TemplateContext
## Details
TemplateContext.GetMemberAccessor()
_memberAccessors
Type
src/Scriban/TemplateContext.cs
GetMemberAccessorImpl()
TypedObjectAccessor(type, _keyComparer, MemberFilter, MemberRenamer)
src/Scriban/TemplateContext.cs
TypedObjectAccessor
PrepareMembers()
src/Scriban/Runtime/Accessors/TypedObjectAccessor.cs
ScriptMemberExpression.GetValue()
src/Scriban/Syntax/Expressions/ScriptMemberExpression.cs
TemplateContext.Reset()
_memberAccessors
src/Scriban/TemplateContext.cs
TemplateContext.MemberFilter
TemplateContext.MemberFilter
## Proof of Concept
## Setup
mkdir scriban-poc2
cd scriban-poc2
dotnet new console --frame
Wiz
GHSA-x6m9-38vm-2xhf Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
[MEDIUM] GHSA-x6m9-38vm-2xhf Impact, Exploitability, and Mitigation Steps | Wiz
## GHSA-x6m9-38vm-2xhf :
C# vulnerability analysis and mitigation
## Summary
TemplateContext.Reset()
TemplateContext
CachedTemplates
TemplateContext
ITemplateLoader
TemplateLoader.Load()
## Details
## 8.6
Score
Published March 24, 2026
Severity HIGH
CNA Score N/A
Affected Technologies
C#
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
scriban
Sources
NVD
NuGet Severity HIGH Has Fix Added at: Mar 25, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related C# vulnerabilities:
CVE ID
Severity
Score
Wiz
CVE-2026-27798 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
CVE-2026-27798 [MEDIUM] CVE-2026-27798 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27798 :
C# vulnerability analysis and mitigation
-wavelet-denoise
Source : NVD
## 7.1
Score
Published February 26, 2026
Severity HIGH
CNA Score 4.0
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libMagick++-devel
cpe:2.3:a:imagemagick:imagemagick
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21, 3.22, 3.23, edge Severity HIGH Has Fix Added at: Mar 02, 2026
Chainguard Has Fix Added at: Mar 02, 2026
Debian 11, 12, 13, 14 Severity HIGH Has Fix Added at: Mar 02, 2026
Echo Severity HIGH Has Fix Added at: Mar 02, 2026
NuGet
Wiz
CVE-2026-26283 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.2
CVE-2026-26283 [MEDIUM] CVE-2026-26283 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-26283 :
C# vulnerability analysis and mitigation
continue
Source : NVD
## 7.5
Score
Published February 24, 2026
Severity HIGH
CNA Score 6.2
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
perl-PerlMagick
ImageMagick-debuginfo
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21, 3.22, 3.23, edge Severity HIGH Has Fix Added at: Mar 02, 2026
Chainguard Has Fix Added at: Feb 24, 2026
Debian 11, 12, 13, 14 Severity HIGH Has Fix Added at: Feb 24, 2026
Echo Severity HIGH Has Fix Added at: Feb 24, 2026
NuGet Severity MEDIUM Has Fix
Wiz
CVE-2026-25970 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-25970 [MEDIUM] CVE-2026-25970 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25970 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a signed integer overflow vulnerability in ImageMagick's SIXEL decoder allows an attacker to trigger memory corruption and denial of service when processing a maliciously crafted SIXEL image file. The vulnerability occurs during buffer reallocation operations where pointer arithmetic using signed 32-bit integers overflows. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
Source : NVD
## 7.5
Score
Published February 24, 2026
Severity HIGH
CNA Score 5.3
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/
Wiz
CVE-2026-25988 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-25988 [MEDIUM] CVE-2026-25988 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25988 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, sometimes msl.c fails to update the stack index, so an image is stored in the wrong slot and never freed on error, causing leaks. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
Source : NVD
## 7.5
Score
Published February 24, 2026
Severity HIGH
CNA Score 5.3
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Magick.NET-Q16-HDRI-arm64
Magick.NET-Q16-OpenMP-x86
Sources
Alpine 3.10
Wiz
CVE-2026-33536 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
CVE-2026-33536 [MEDIUM] CVE-2026-33536 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33536 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9.13-43, due to an incorrect return value on certain platforms a pointer is incremented past the end of a buffer that is on the stack and that could result in an out of bounds write. Versions 7.1.2-18 and 6.9.13-43 patch the issue.
Source : NVD
## 4.7
Score
Published March 26, 2026
Severity MEDIUM
CNA Score 5.1
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
ImageMagick
ImageMagick-c++-devel
Sour
Wiz
CVE-2026-31834 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.2
CVE-2026-31834 [HIGH] CVE-2026-31834 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-31834 :
C# vulnerability analysis and mitigation
Umbraco is an ASP.NET CMS. From 15.3.1 to before 16.5.1 and 17.2.2, A privilege escalation vulnerability has been identified in Umbraco CMS. Under certain conditions, authenticated backoffice users with permission to manage users, may be able to elevate their privileges due to insufficient authorization enforcement when modifying user group memberships. The affected functionality does not properly validate whether a user has sufficient privileges to assign highly privileged roles. This vulnerability is fixed in 16.5.1 and 17.2.2.
Source : NVD
## 7.2
Score
Published March 10, 2026
Severity HIGH
CNA Score 7.2
Affected Technologies
C#
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Du
Wiz
CVE-2026-25576 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.1
CVE-2026-25576 [MEDIUM] CVE-2026-25576 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25576 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in multiple raw image format handles. The vulnerability occurs when processing images with -extract dimensions larger than -size dimensions, causing out-of-bounds memory reads from a heap-allocated buffer. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
Source : NVD
## 5.5
Score
Published February 24, 2026
Severity MEDIUM
CNA Score 5.1
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.3
Exploitation Probabil
Wiz
CVE-2025-68469 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.0
CVE-2025-68469 [LOW] CVE-2025-68469 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68469 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.1-14, ImageMagick crashes when processing a crafted TIFF file. Version 7.1.1-14 fixes the issue.
Source : NVD
## 2
Score
Published December 18, 2025
Severity LOW
CNA Score 2.0
Affected Technologies
C#
ImageMagick
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Magick.NET-Q16-HDRI-x64
ImageMagick-perl
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21 Severity LOW Has Fix Added at: Dec 31, 2025
Alpi
Wiz
GHSA-7jxj-rpx7-ph2c Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
GHSA-7jxj-rpx7-ph2c Impact, Exploitability, and Mitigation Steps | Wiz
## GHSA-7jxj-rpx7-ph2c :
C# vulnerability analysis and mitigation
## Impact
Protected files uploaded through Umbraco Forms may be served to unauthenticated users when a CDN or caching layer is present and ImageSharp processes the request. ImageSharp sets aggressive cache headers by default, which can cause intermediary caches to store and serve files that should require authentication.
## Patches
This issue affects all (supported) versions Umbraco Forms and is patched in 13.9.0, 16.4.0 and 17.1.0.
## Workarounds
Startup.cs
Program.cs
app.UseStaticFiles()
app.Use(async (context, next) =>
{
var path = context.Request.Path.Value;
if (!string.IsNullOrEmpty(path) && path.StartsWith("/media/forms/upload/", StringComparison.OrdinalIgnoreCase))
{
context.Response.OnStarting(() =>
{
Wiz
CVE-2025-66628 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-66628 [HIGH] CVE-2025-66628 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-66628 :
C# vulnerability analysis and mitigation
ImageMagick is a software suite to create, edit, compose, or convert bitmap images. In versions 7.1.2-9 and prior, the TIM (PSX TIM) image parser contains a critical integer overflow vulnerability in its ReadTIMImage function (coders/tim.c). The code reads width and height (16-bit values) from the file header and calculates image_size = 2 * width * height without checking for overflow. On 32-bit systems (or where size_t is 32-bit), this calculation can overflow if width and height are large (e.g., 65535), wrapping around to a small value. This results in a small heap allocation via AcquireQuantumMemory and later operations relying on the dimensions can trigger an out of bounds read. This issue is fixed in version 7.1.2-10.
Sou
Wiz
CVE-2026-25989 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-25989 [HIGH] CVE-2026-25989 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25989 :
C# vulnerability analysis and mitigation
>
>=
(size_t)
Source : NVD
## 7.5
Score
Published February 24, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
ImageMagick-doc
ImageMagick-config-7-SUSE
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21, 3.22, 3.23, edge Severity HIGH Has Fix Added at: Mar 02, 2026
Chainguard Has Fix Added at: Feb 24, 2026
Debian 11, 12, 13, 14 Severity HIGH Has Fix Added at: Feb 24, 2026
Echo Severity HIGH Has Fix Added at: Feb 24, 2026
NuGet Severity HI
Wiz
CVE-2026-28691 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-28691 [HIGH] CVE-2026-28691 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28691 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an uninitialized pointer dereference vulnerability exists in the JBIG decoder due to a missing check. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
Source : NVD
## 7.5
Score
Published March 10, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 17.3
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
Magick.NET-Q16-HDRI-AnyCPU
Magick.NET-Q16-HDRI-OpenMP-x64
Sources
Alpine 3.10, 3.11, 3.12, 3.13
Wiz
CVE-2026-31832 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-31832 [MEDIUM] CVE-2026-31832 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-31832 :
C# vulnerability analysis and mitigation
Umbraco is an ASP.NET CMS. From 14.0.0 to before 16.5.1 and 17.2.2, A broken object-level authorization vulnerability exists in a backoffice API endpoint that allows authenticated users to assign domain-related data to content nodes without proper authorization checks. The issue is caused by insufficient authorization enforcement on the affected API endpoint, whereby via an API call, domains can be set on content nodes that the editor does not have permission to access (either via user group privileges or start nodes). This vulnerability is fixed in 16.5.1 and 17.2.2.
Source : NVD
## 5.4
Score
Published March 10, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
C#
Has Public Exploit No
Has CISA KEV Exploit N
Wiz
CVE-2026-28692 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.8
CVE-2026-28692 [MEDIUM] CVE-2026-28692 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28692 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, MAT decoder uses 32-bit arithmetic due to incorrect parenthesization resulting in a heap over-read. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
Source : NVD
## 4.8
Score
Published March 10, 2026
Severity MEDIUM
CNA Score 4.8
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
ImageMagick-perl-debuginfo
Magick.NET-Q16-arm64
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.1
Wiz
CVE-2025-64113 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.3
CVE-2025-64113 [CRITICAL] CVE-2025-64113 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64113 :
C# vulnerability analysis and mitigation
Emby Server is a user-installable home media server. Versions below 4.9.1.81 allow an attacker to gain full administrative access to an Emby Server (for Emby Server administration, not at the OS level). Other than network access, no specific preconditions need to be fulfilled for a server to be vulnerable. This issue is fixed in version 4.9.1.81.
Source : NVD
## 9.3
Score
Published December 9, 2025
Severity CRITICAL
CNA Score 9.3
Affected Technologies
C#
Homebrew
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
MediaBrowser.Server.Core
emby
Sources
Wiz
GHSA-5rpf-x9jg-8j5p Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
[MEDIUM] GHSA-5rpf-x9jg-8j5p Impact, Exploitability, and Mitigation Steps | Wiz
## GHSA-5rpf-x9jg-8j5p :
C# vulnerability analysis and mitigation
TemplateContext.LimitToString
0
LoopLimit
using Scriban;
string maliciousTemplate =
@"
{{
a = ""A""
for i in 1..30
a = a + a
end
a
}}";
var template = Template.Parse(maliciousTemplate);
var context = new TemplateContext();
try
{
template.Render(context);
}
catch (Exception ex)
{
Console.WriteLine("\nException: " + ex.Message);
}
LimitToString
public int LimitToString { get; set; } = 1048576;
Source : NVD
## 5.3
Score
Published March 19, 2026
Severity MEDIUM
CNA Score N/A
Affected Technologies
C#
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Wiz
CVE-2026-24836 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.6
CVE-2026-24836 [HIGH] CVE-2026-24836 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24836 :
C# vulnerability analysis and mitigation
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 9.0.0 and prior to versions 9.13.10 and 10.2.0, extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Versions 9.13.10 and 10.2.0 contain a fix for the issue.
Source : NVD
## 5.4
Score
Published January 28, 2026
Severity MEDIUM
CNA Score 7.6
Affected Technologies
C#
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
DotNetNuke.Core
Sources
NVD
NuGet Severity H
Wiz
GHSA-rvv3-g6hj-g44x Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
[MEDIUM] GHSA-rvv3-g6hj-g44x Impact, Exploitability, and Mitigation Steps | Wiz
## GHSA-rvv3-g6hj-g44x :
C# vulnerability analysis and mitigation
## Summary
StackOverflowException
## Description
StackOverflowException
## Impact
Availability: An attacker can crash the application server, leading to a complete Denial of Service.
Process Termination: Unlike standard exceptions, this terminates the entire process, not just the individual request thread.
## Proof of Concept (PoC)
The following C# code demonstrates the crash by creating a nested "Circular" object graph and attempting to map it:
class Circular { public Circular Self { get; set; } }
// Setup configuration
var config = new MapperConfiguration(cfg => {
cfg.CreateMap();
});
var mapper = config.CreateMapper();
// Create a deeply nested object (28,000+ levels)
var root = new Circular();
var curre
Wiz
CVE-2026-23952 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-23952 [MEDIUM] CVE-2026-23952 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23952 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL (Magick Scripting Language) parser when processing tags before images are loaded. This can lead to DoS attack due to assertion failure (debug builds) or NULL pointer dereference (release builds). This issue is fixed in version 14.10.2.
Source : NVD
## 7.5
Score
Published January 22, 2026
Severity HIGH
CNA Score 6.5
Affected Technologies
C#
ImageMagick
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.6
Exploitation Probability (EPSS) N/A
Affected
Wiz
CVE-2026-32259 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.7
CVE-2026-32259 [MEDIUM] CVE-2026-32259 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32259 :
ImageMagick vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9.13-41, when a memory allocation fails in the sixel encoder it would be possible to write past the end of a buffer on the stack. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
Source : NVD
## 6.7
Score
Published March 12, 2026
Severity MEDIUM
CNA Score 6.7
Affected Technologies
ImageMagick
Linux Red Hat
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
ImageMagick-c++-devel
ImageMagick-devel
Sources
Alpine 3.10, 3.1
Wiz
CVE-2026-25987 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-25987 [MEDIUM] CVE-2026-25987 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25987 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in the MAP image decoder when processing crafted MAP files, potentially leading to crashes or unintended memory disclosure during image decoding. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
Source : NVD
## 9.1
Score
Published February 24, 2026
Severity CRITICAL
CNA Score 5.3
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Magick.NE
Wiz
CVE-2026-25795 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-25795 [MEDIUM] CVE-2026-25795 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25795 :
C# vulnerability analysis and mitigation
ReadSFWImage()
coders/sfw.c
read_info
filename
Source : NVD
## 7.5
Score
Published February 24, 2026
Severity HIGH
CNA Score 5.3
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
ImageMagick-config-7-upstream-limited
libMagick++-7_Q16HDRI5-32bit
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21, 3.22, 3.23, edge Severity HIGH Has Fix Added at: Mar 02, 2026
Chainguard Has Fix Added at: Feb 24, 2026
Debian 11, 12, 13, 14 Severity HIGH Has Fix Added at: Feb 24, 2026
Echo Seve
Wiz
CVE-2025-68924 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-68924 [HIGH] CVE-2025-68924 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68924 :
C# vulnerability analysis and mitigation
In Umbraco UmbracoForms through 8.13.16, an authenticated attacker can supply a malicious WSDL (aka Webservice) URL as a data source for remote code execution.
Source : NVD
## 7.5
Score
Published January 16, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
C#
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 28.2
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
UmbracoForms
Sources
NVD
NuGet Severity CRITICAL No Fix Added at: Jan 14, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related C# vul
Wiz
CVE-2026-23876 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.1
CVE-2026-23876 [HIGH] CVE-2026-23876 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23876 :
ImageMagick vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-13 and 6.9.13-38, a heap buffer overflow vulnerability in the XBM image decoder (ReadXBMImage) allows an attacker to write controlled data past the allocated heap buffer when processing a maliciously crafted image file. Any operation that reads or identifies an image can trigger the overflow, making it exploitable via common image upload and processing pipelines. Versions 7.1.2-13 and 6.9.13-38 fix the issue.
Source : NVD
## 9.8
Score
Published January 20, 2026
Severity CRITICAL
CNA Score 8.1
Affected Technologies
ImageMagick
Linux Red Hat
Has Public Exploit Yes
Has CISA KEV Exploit No
CI
Wiz
CVE-2026-33535 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
CVE-2026-33535 [MEDIUM] CVE-2026-33535 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33535 :
C# vulnerability analysis and mitigation
display
Source : NVD
## 5.5
Score
Published March 26, 2026
Severity MEDIUM
CNA Score 4.0
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Magick.NET-Q8-x64
Magick.NET-Q16-HDRI-arm64
Sources
Chainguard Has Fix Added at: Mar 29, 2026
Debian 11, 12, 13 Severity MEDIUM No Fix Added at: Mar 29, 2026
Debian 14 Severity MEDIUM Has Fix Added at: Mar 29, 2026
Echo Severity MEDIUM Has Fix Added at: Mar 29, 2026
NuGet Severity MEDIUM Has Fix Added at: Mar 29, 2026
Homebrew Severity MEDIUM Has Fix Added at: Apr 05, 2026
Wiz
GHSA-qp59-x883-77qv Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
GHSA-qp59-x883-77qv Impact, Exploitability, and Mitigation Steps | Wiz
## GHSA-qp59-x883-77qv :
C# vulnerability analysis and mitigation
## Summary
LoadOpenCLDeviceBenchmark()
MagickCore/opencl.c
platform_name
vendor_name
name
version
## Details
MagickCore/opencl.c
LoadOpenCLDeviceBenchmark()
device_benchmark
/>
Vulnerable Code (lines 908-910):
token=(char *) RelinquishMagickMemory(token);
device_benchmark=(MagickCLDeviceBenchmark *) RelinquishMagickMemory(
device_benchmark); // BUG: members (platform_name, vendor_name, name, version) not freed!
/>
c device_benchmark->platform_name=(char *) RelinquishMagickMemory(device_benchmark->platform_name); device_benchmark->vendor_name=(char *) RelinquishMagickMemory(device_benchmark->vendor_name); device_benchmark->name=(char *) RelinquishMagickMemory(device_benchmark->name); device_benchmark->ve
Wiz
CVE-2026-24484 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-24484 [MEDIUM] CVE-2026-24484 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24484 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, Magick fails to check for multi-layer nested mvg conversions to svg, leading to DoS. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
Source : NVD
## 5.3
Score
Published February 24, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
ImageMagick-c++
ImageMagick-config-7-upstream-limited
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.1
Wiz
CVE-2026-25898 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-25898 [MEDIUM] CVE-2026-25898 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25898 :
C# vulnerability analysis and mitigation
GetPixelIndex()
Quantum
Source : NVD
## 9.1
Score
Published February 24, 2026
Severity CRITICAL
CNA Score 6.5
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libMagickWand-7_Q16HDRI10-32bit
ImageMagick-config-7-upstream-websafe
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21, 3.22, 3.23, edge Severity CRITICAL Has Fix Added at: Mar 02, 2026
Chainguard Has Fix Added at: Feb 24, 2026
Debian 11, 12, 13, 14 Severity CRITICAL Has Fix Added at: Feb 24, 2026
Echo Severity CRITI
Wiz
CVE-2026-25969 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-25969 [MEDIUM] CVE-2026-25969 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25969 :
C# vulnerability analysis and mitigation
coders/ashlar.c
WriteASHLARImage
Source : NVD
## 7.5
Score
Published February 24, 2026
Severity HIGH
CNA Score 5.3
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 17.8
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
libMagickWand-7_Q16HDRI10
seal-ImageMagick
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21, 3.22, 3.23, edge Severity HIGH Has Fix Added at: Mar 02, 2026
Chainguard Has Fix Added at: Feb 24, 2026
Debian 11, 12 Severity HIGH No Fix Added at: Feb 24, 2026
Debian 13, 14 Severity HIGH Has Fix Added at: Feb 24, 202
Wiz
CVE-2025-68618 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2025-68618 [MEDIUM] CVE-2025-68618 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68618 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, using Magick to read a malicious SVG file resulted in a DoS attack. Version 7.1.2-12 fixes the issue.
Source : NVD
## 7.5
Score
Published December 30, 2025
Severity HIGH
CNA Score 5.3
Affected Technologies
C#
ImageMagick
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 27.8
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
ImageMagick-config-7-upstream-websafe
perl-PerlMagick
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21, edge Severity HIGH H
Wiz
CVE-2026-25968 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.4
CVE-2026-25968 [HIGH] CVE-2026-25968 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25968 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a stack buffer overflow occurs when processing the an attribute in msl.c. A long value overflows a fixed-size stack buffer, leading to memory corruption. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
Source : NVD
## 9.8
Score
Published February 24, 2026
Severity CRITICAL
CNA Score 7.4
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 19.1
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
ImageMagick-perl-debuginfo
Magick.NET-Q8-arm
Wiz
CVE-2025-67290 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.1
CVE-2025-67290 [MEDIUM] CVE-2025-67290 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-67290 :
C# vulnerability analysis and mitigation
A stored cross-site scripting (XSS) vulnerability in the Page Settings module of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Excerpt field.
Source : NVD
## 6.1
Score
Published December 22, 2025
Severity MEDIUM
CNA Score 6.1
Affected Technologies
C#
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 15.7
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
Piranha
Sources
NVD
NuGet Severity LOW No Fix Added at: Dec 23, 2025
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitab
Wiz
GHSA-c875-h985-hvrc Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
[MEDIUM] GHSA-c875-h985-hvrc Impact, Exploitability, and Mitigation Steps | Wiz
## GHSA-c875-h985-hvrc :
C# vulnerability analysis and mitigation
## Summary
LoopLimit
{{ 1..1000000 | array.size }}
LoopLimit
## Details
Source : NVD
## 7.5
Score
Published March 24, 2026
Severity HIGH
CNA Score N/A
Affected Technologies
C#
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
scriban
Sources
NVD
NuGet Severity HIGH Has Fix Added at: Mar 25, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related C# vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Wiz
CVE-2026-24485 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-24485 [HIGH] CVE-2026-24485 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24485 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, when a PCD file does not contain a valid Sync marker, the DecodeImage() function becomes trapped in an infinite loop while searching for the Sync marker, causing the program to become unresponsive and continuously consume CPU resources, ultimately leading to system resource exhaustion and denial of service. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
Source : NVD
## 7.5
Score
Published February 24, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation
Wiz
CVE-2026-30936 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-30936 [MEDIUM] CVE-2026-30936 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-30936 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a crafted image could cause an out of bounds heap write inside the WaveletDenoiseImage method. When processing a crafted image with the -wavelet-denoise operation an out of bounds write can occur. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
Source : NVD
## 5.5
Score
Published March 10, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Im
Wiz
CVE-2026-21218 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-21218 [HIGH] CVE-2026-21218 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21218 :
C# vulnerability analysis and mitigation
Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network.
Source : NVD
## 7.5
Score
Published February 10, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
C#
.NET SDK
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 13.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
dotnet8
cpe:2.3:a:microsoft:.net
Sources
Alpine 3.20, 3.21, 3.23 Severity HIGH Has Fix Added at: Feb 21, 2026
Alpine 3.22 Severity HIGH Has Fix Added at: Feb 24, 2026
Alpine edge Severity HIGH Has Fix Added at: Feb 12, 2026
Chainguard Has Fix Added at: Feb 24, 2026
Wiz
GHSA-mvm6-f9r3-fgfx Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
GHSA-mvm6-f9r3-fgfx Impact, Exploitability, and Mitigation Steps | Wiz
## GHSA-mvm6-f9r3-fgfx :
C# vulnerability analysis and mitigation
## Summary
This notification is related to the CloudFront signing utilities in the AWS SDK for .NET, which are used to generate Amazon CloudFront signed URLs and signed cookies. A defense-in-depth enhancement has been implemented to improve handling of special characters, such as double quotes and backslashes, in input values.
## Impact
The CloudFront signing utilities build policy documents that define access restrictions for signed URLs and cookies. If an application passes unsanitized input containing special characters to these utilities, the resulting policy document may not reflect the application's intended access restrictions. While the SDK was functioning safely within the requirements of the shared responsi
Wiz
GHSA-m2p3-hwv5-xpqw Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
GHSA-m2p3-hwv5-xpqw Impact, Exploitability, and Mitigation Steps | Wiz
## GHSA-m2p3-hwv5-xpqw :
C# vulnerability analysis and mitigation
## Summary
LimitToString
b5ac4bf
_currentToStringLength
ObjectToString
TemplateContext.Write(SourceSpan, object)
ObjectToString
StringBuilderOutput
## Details
TemplateContext.Helpers.cs
ObjectToString
// src/Scriban/TemplateContext.Helpers.cs:89-111
public virtual string ObjectToString(object value, bool nested = false)
{
if (_objectToStringLevel == 0)
{
_currentToStringLength = 0; // 0 && _objectToStringLevel == 1 && result != null && result.Length >= LimitToString)
{
return result + "...";
}
return result;
}
// ...
}
TemplateContext.Write(SourceSpan, object)
ObjectToString
// src/Scriban/TemplateContext.cs:693-701
public virtual TemplateContext Write(SourceSpan span, object textAsObject)
{
if (textAsObje
Wiz
CVE-2026-28693 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.1
CVE-2026-28693 [HIGH] CVE-2026-28693 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28693 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an integer overflow in DIB coder can result in out of bounds read or write. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
Source : NVD
## 8.1
Score
Published March 10, 2026
Severity HIGH
CNA Score 8.1
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 18.5
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
perl-PerlMagick
ImageMagick-debuginfo
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.
Wiz
CVE-2025-14759 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.0
CVE-2025-14759 [MEDIUM] CVE-2025-14759 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14759 :
C# vulnerability analysis and mitigation
Missing cryptographic key commitment in the Amazon S3 Encryption Client for .NET may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3's metadata record.
To mitigate this issue, upgrade Amazon S3 Encryption Client for .NET to version 3.2.0 or later.
Source : NVD
## 6
Score
Published December 17, 2025
Severity MEDIUM
CNA Score 6.0
Affected Technologies
C#
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Amazon.Extensions
Wiz
CVE-2026-25798 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-25798 [MEDIUM] CVE-2026-25798 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25798 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a NULL pointer dereference in ClonePixelCacheRepository allows a remote attacker to crash any application linked against ImageMagick by supplying a crafted image file, resulting in denial of service. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
Source : NVD
## 7.5
Score
Published February 24, 2026
Severity HIGH
CNA Score 5.3
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 19.4
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
Ima
Wiz
CVE-2026-25794 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.2
CVE-2026-25794 [HIGH] CVE-2026-25794 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25794 :
C# vulnerability analysis and mitigation
WriteUHDRImage
coders/uhdr.c
int
int
Source : NVD
## 8.2
Score
Published February 24, 2026
Severity HIGH
CNA Score 8.2
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 18
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
Magick.NET-Q16-HDRI-AnyCPU
Magick.NET-Q16-HDRI-x86
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21, 3.22, 3.23, edge Severity HIGH Has Fix Added at: Feb 24, 2026
Chainguard Has Fix Added at: Feb 24, 2026
Debian 11, 12 Severity HIGH No Fix Added at: Feb 24, 2026
Debian 13, 14 Severity HIGH Has Fix Added at:
Wiz
CVE-2026-25897 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-25897 [MEDIUM] CVE-2026-25897 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25897 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, an Integer Overflow vulnerability exists in the sun decoder. On 32-bit systems/builds, a carefully crafted image can lead to an out of bounds heap write. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
Source : NVD
## 9.8
Score
Published February 24, 2026
Severity CRITICAL
CNA Score 6.5
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 19.2
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
libMagick++-devel
libMagickCore-7_Q16HDRI10-
Wiz
CVE-2026-24481 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-24481 [HIGH] CVE-2026-24481 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24481 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap information disclosure vulnerability exists in ImageMagick's PSD (Adobe Photoshop) format handler. When processing a maliciously crafted PSD file containing ZIP-compressed layer data that decompresses to less than the expected size, uninitialized heap memory is leaked into the output image. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
Source : NVD
## 7.5
Score
Published February 24, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probabilit
Wiz
CVE-2026-24838 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.1
CVE-2026-24838 [CRITICAL] CVE-2026-24838 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24838 :
C# vulnerability analysis and mitigation
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to versions 9.13.10 and 10.2.0, module title supports richtext which could include scripts that would execute in certain scenarios. Versions 9.13.10 and 10.2.0 contain a fix for the issue.
Source : NVD
## 5.4
Score
Published January 28, 2026
Severity MEDIUM
CNA Score 9.1
Affected Technologies
C#
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
DotNetNuke.Core
Sources
NVD
NuGet Severity CRITICAL Has Fix Added at: Jan 29, 2026
## Get a
Wiz
CVE-2021-47776 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.9
CVE-2021-47776 [MEDIUM] CVE-2021-47776 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2021-47776 :
C# vulnerability analysis and mitigation
Umbraco CMS v8.14.1 contains a server-side request forgery vulnerability that allows attackers to manipulate baseUrl parameters in multiple dashboard and help controller endpoints. Attackers can craft malicious requests to the GetContextHelpForPage, GetRemoteDashboardContent, and GetRemoteDashboardCss endpoints to trigger unauthorized server-side requests to external hosts.
Source : NVD
## 6.9
Score
Published January 15, 2026
Severity MEDIUM
CNA Score 6.9
Affected Technologies
C#
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
UmbracoCms
Sources
NVD
Wiz
CVE-2026-25967 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.4
CVE-2026-25967 [HIGH] CVE-2026-25967 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25967 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-15, a stack-based buffer overflow exists in the ImageMagick FTXT image reader. A crafted FTXT file can cause out-of-bounds writes on the stack, leading to a crash. Version 7.1.2-15 contains a patch.
Source : NVD
## 7.5
Score
Published February 24, 2026
Severity HIGH
CNA Score 7.4
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 17.8
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
Magick.NET-Q8-x86
Magick.NET-Q16-HDRI-AnyCPU
Sources
Alpine 3.10, 3.1
Wiz
CVE-2025-67288 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.7
CVE-2025-67288 [LOW] CVE-2025-67288 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-67288 :
C# vulnerability analysis and mitigation
An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system administrator who is implementing Umbraco CMS in their environment, not to Umbraco CMS itself, a related issue to CVE-2023-49279.
Source : NVD
## 10
Score
Published December 22, 2025
Severity CRITICAL
CNA Score 10.0
Affected Technologies
C#
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.9
Exploitation Probability (EPSS) N/A
Affected packages and l
Wiz
CVE-2026-22770 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-22770 [MEDIUM] CVE-2026-22770 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22770 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. The BilateralBlurImage method will allocate a set of double buffers inside AcquireBilateralTLS. But, in versions prior to 7.1.2-13, the last element in the set is not properly initialized. This will result in a release of an invalid pointer inside DestroyBilateralTLS when the memory allocation fails. Version 7.1.2-13 contains a patch for the issue.
Source : NVD
## 9.8
Score
Published January 20, 2026
Severity CRITICAL
CNA Score 6.5
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 20.7
Exploitati
2026-03-26
Published