Buffer Overflow Vulnerability in ImageMagick by ImageMagick Studio LLC
CVE-2026-30931

6.8MEDIUM

Key Information:

Vendor
CVE Published:
9 March 2026

What is CVE-2026-30931?

ImageMagick, a widely used open-source software for image editing, has a vulnerability that involves a heap-based buffer overflow in the UHDR encoder. This issue can lead to an out of bounds write due to the truncation of values, potentially impacting the security and stability of applications relying on this image processing tool. Users are strongly advised to upgrade to version 7.1.2-16 or later to mitigate this risk.

Affected Version(s)

ImageMagick < 7.1.2-16

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.