Off-by-One Error in ImageMagick MSL Decoder Affecting Multiple Versions
CVE-2026-40312
6.2MEDIUM
What is CVE-2026-40312?
A vulnerability exists in the ImageMagick software due to an off-by-one error in its MSL decoder, which can lead to a program crash when processing specially crafted MSL files. This issue affects versions prior to 7.1.2-19 and has been resolved in the latest release. Users are advised to upgrade to the fixed version to enhance their security posture against potential exploitation.
Affected Version(s)
ImageMagick < 7.1.2-19