Heap Buffer Overflow in ImageMagick Affects Digital Image Processing
CVE-2026-62363

5MEDIUM

Key Information:

Vendor
CVE Published:
30 July 2026

What is CVE-2026-62363?

ImageMagick, a widely used software suite for editing and processing digital images, is affected by a heap buffer overflow vulnerability. This vulnerability exists in versions prior to 7.1.2-27, specifically within the fx operation, where a crafted argument can lead to a heap buffer overwrite. This poses a security risk as it may allow an attacker to exploit this flaw to execute arbitrary code or cause a denial of service. Users are strongly advised to update to version 7.1.2-27 or later to mitigate this vulnerability.

Affected Version(s)

ImageMagick < 7.1.2-27

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.