{"id":"CVE-2026-103118","title":"A vulnerability was detected in GraphicsMagick up to 1.3.47","summary":"A vulnerability was detected in GraphicsMagick up to 1.3.47. Affected by this vulnerability is the function ExtractPostscript of the file coders/wpg.c of the component WPG File Handler. Performing a manipulation results in uncontrolled r…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","cwe":["CWE-404","CWE-674"],"product":"GraphicsMagick","affected":["GraphicsMagick 1.3.0","GraphicsMagick 1.3.1","GraphicsMagick 1.3.2","GraphicsMagick 1.3.3","GraphicsMagick 1.3.4","GraphicsMagick 1.3.5","GraphicsMagick 1.3.6","GraphicsMagick 1.3.7","GraphicsMagick 1.3.8","GraphicsMagick 1.3.9","GraphicsMagick 1.3.10","GraphicsMagick 1.3.11","GraphicsMagick 1.3.12","GraphicsMagick 1.3.13","GraphicsMagick 1.3.14","GraphicsMagick 1.3.15","GraphicsMagick 1.3.16","GraphicsMagick 1.3.17","GraphicsMagick 1.3.18","GraphicsMagick 1.3.19","GraphicsMagick 1.3.20","GraphicsMagick 1.3.21","GraphicsMagick 1.3.22","GraphicsMagick 1.3.23","GraphicsMagick 1.3.24","GraphicsMagick 1.3.25","GraphicsMagick 1.3.26","GraphicsMagick 1.3.27","GraphicsMagick 1.3.28","GraphicsMagick 1.3.29","GraphicsMagick 1.3.30","GraphicsMagick 1.3.31","GraphicsMagick 1.3.32","GraphicsMagick 1.3.33","GraphicsMagick 1.3.34","GraphicsMagick 1.3.35","GraphicsMagick 1.3.36","GraphicsMagick 1.3.37","GraphicsMagick 1.3.38","GraphicsMagick 1.3.39","GraphicsMagick 1.3.40","GraphicsMagick 1.3.41","GraphicsMagick 1.3.42","GraphicsMagick 1.3.43","GraphicsMagick 1.3.44","GraphicsMagick 1.3.45","GraphicsMagick 1.3.46","GraphicsMagick 1.3.47"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T14:17:27.347","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-103118","references":[{"url":"https://foss.heptapod.net/graphicsmagick/graphicsmagick/-/commit/627b5b1b2fc2","label":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-103118","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/954970","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/411874","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/411874/cti","label":"cna@vuldb.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-30T14:05:17.367Z","slug":"CVE-2026-103118","body":"## Overview\n\nA vulnerability was detected in GraphicsMagick up to 1.3.47. Affected by this vulnerability is the function ExtractPostscript of the file coders/wpg.c of the component WPG File Handler. Performing a manipulation results in uncontrolled recursion. The attack may be initiated remotely. The patch is named 627b5b1b2fc2. It is suggested to install a patch to address this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}