CVE-2026-46557
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-23, due to a missing depth check a stack overflow can occur in the fx operation by passing a crafted argument. This issue has been patched in version 7.1.2-23.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.2
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.12%
- CWE
- CWE-674
- Published
- 2026-06-10
- Last modified
- 2026-09-14
Affected products
- ImageMagick ImageMagick
Weakness type
Related vulnerabilities
- CVE-2026-33498 — Parse Server: Query condition depth bypass via pre-validation transform pipeline
- CVE-2026-32944 — Parse Server crash via deeply nested query condition operators
- CVE-2025-66031 — node-forge ASN.1 Unbounded Recursion
- CVE-2025-54858 — BIG-IP Advanced WAF and ASM vulnerability
- CVE-2025-9624 — OpenSearch 3.2.0 - Nested Boolean/Disjunction asymmetric DoS
- CVE-2026-33508 — Parse Server: LiveQuery subscription query depth bypass
- CVE-2026-72686 — Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
- CVE-2026-72679 — Uncontrolled Recursion in Elasticsearch Leading to Denial of Service