Heap Write Overflow Vulnerability in ImageMagick JXL Encoder
CVE-2026-40183
5.5MEDIUM
What is CVE-2026-40183?
ImageMagick is widely utilized for editing and manipulating digital images. A vulnerability has been identified in the JXL encoder, specifically a heap write overflow when encoding images as 16-bit floats. This issue is present in versions prior to 7.1.2-19 and poses a risk of memory corruption. Users are advised to upgrade to the patched version 7.1.2-19 to safeguard against potential exploitation.
Affected Version(s)
ImageMagick < 7.1.2-19