CVE-2026-46521
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, when using LZMA compression in the MIFF encoder an out of bounds write can occur due to a missing check. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.5
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS probability
- 0.11%
- CWE
- CWE-131, CWE-252, CWE-787, CWE-835
- Published
- 2026-06-10
- Last modified
- 2026-09-14
Affected products
- ImageMagick ImageMagick
- ImageMagick ImageMagick
Weakness type
Related vulnerabilities
- CVE-2023-36824 — Heap overflow in COMMAND GETKEYS and ACL evaluation in Redis
- CVE-2024-23622 — IBM Merge Healthcare eFilm Workstation License Server CopySLS_Request3 Buffer Overflow
- CVE-2024-23621 — IBM Merge Healthcare eFilm Workstation License Server Buffer Overflow
- CVE-2021-0254 — Junos OS: Remote code execution vulnerability in overlayd service
- CVE-2020-13585 — An out-of-bounds write vulnerability exists in the PSD Header processing functionality of Accusoft ImageGear 19.8. A spe
- CVE-2023-24819 — RIOT-OS vulnerable to Buffer Overflow during IPHC receive
- CVE-2022-22137 — A memory corruption vulnerability exists in the ioca_mys_rgb_allocate functionality of Accusoft ImageGear 19.10. A speci
- CVE-2021-21793 — An out-of-bounds write vulnerability exists in the JPG sof_nb_comp header processing functionality of Accusoft ImageGear