Buffer Overflow Vulnerability in ImageMagick Software by ImageMagick
CVE-2026-42050

5.5MEDIUM

Key Information:

Vendor
CVE Published:
11 May 2026

What is CVE-2026-42050?

ImageMagick is an open-source software suite for editing and manipulating digital images. A buffer overflow vulnerability exists in earlier versions of ImageMagick (prior to 7.1.2-21 and 6.9.13-46), which can be triggered by a specially crafted MIFF file. When users open such a file in the display tool and select the Load / Update menu item, it could potentially lead to unexpected behavior or compromise system integrity. This issue has been addressed in subsequent releases, ensuring enhanced security for users.

Affected Version(s)

ImageMagick < 6.9.13-46 < 6.9.13-46

ImageMagick >= 7.0.0, < 7.1.2-20 < 7.0.0, 7.1.2-20

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.