CVE-2026-56376Low· 3.7▾ SunlitImageMagick has a possible heap Use After Free vulnerability in its meta coder
▾ Sunlit zone — Low / medium · no exploitation signal
impact 20.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
0.3%
A heap Use After Free vulnerability exists in the meta coder when an allocation fails and a single byte is written to a stale pointer.
==535852==ERROR: AddressSanitizer: heap-use-after-free on address 0x5210000088ff at pc 0x5581bacac14d bp 0x7ffdf667edf0 sp 0x7ffdf667ede0
WRITE of size 1 at 0x5210000088ff thread T0
Magick.NET-Q16-AnyCPU < 14.10.3Magick.NET-Q16-HDRI-AnyCPU < 14.10.3Magick.NET-Q16-HDRI-OpenMP-arm64 < 14.10.3Magick.NET-Q16-HDRI-OpenMP-x64 < 14.10.3Magick.NET-Q16-HDRI-arm64 < 14.10.3Magick.NET-Q16-HDRI-x64 < 14.10.3Magick.NET-Q16-HDRI-x86 < 14.10.3Magick.NET-Q16-OpenMP-arm64 < 14.10.3Magick.NET-Q16-OpenMP-x64 < 14.10.3Magick.NET-Q16-OpenMP-x86 < 14.10.3Magick.NET-Q16-arm64 < 14.10.3Magick.NET-Q8-AnyCPU < 14.10.3Magick.NET-Q8-OpenMP-arm64 < 14.10.3Magick.NET-Q8-OpenMP-x64 < 14.10.3Magick.NET-Q8-arm64 < 14.10.3Magick.NET-Q8-x64 < 14.10.3Magick.NET-Q8-x86 < 14.10.3Upgrade to a patched release:
Magick.NET-Q16-AnyCPU 14.10.3Magick.NET-Q16-HDRI-AnyCPU 14.10.3Magick.NET-Q16-HDRI-OpenMP-arm64 14.10.3Magick.NET-Q16-HDRI-OpenMP-x64 14.10.3Magick.NET-Q16-HDRI-arm64 14.10.3Magick.NET-Q16-HDRI-x64 14.10.3Magick.NET-Q16-HDRI-x86 14.10.3Magick.NET-Q16-OpenMP-arm64 14.10.3Magick.NET-Q16-OpenMP-x64 14.10.3Magick.NET-Q16-OpenMP-x86 14.10.3Magick.NET-Q16-arm64 14.10.3Magick.NET-Q8-AnyCPU 14.10.3Magick.NET-Q8-OpenMP-arm64 14.10.3Magick.NET-Q8-OpenMP-x64 14.10.3Magick.NET-Q8-arm64 14.10.3Magick.NET-Q8-x64 14.10.3Magick.NET-Q8-x86 14.10.3Connected by shared product, vendor, weakness, or advisory.
GHSA-8g9f-ccmr-vfvgMedium· 3.7Duplicate Advisory: ImageMagick has a possible heap Use After Free vulnerability in its meta coder
GHSA-qvxh-prvr-85w2Low· 3.7ImageMagick: Use-After-Free in FormatMagickCaption when memory allocation fails
CVE-2026-55510Medium· 5.5ImageMagick: Use-After-Free in crafted 8BIM when identifying an image
GHSA-qh5g-q395-cx4jLow· 3.7ImageMagick: Heap-use-after-free via XMP profile could result in a crash
GHSA-6jwg-7q3p-5fqmLow· 3.7ImageMagick: Use-After-Free when freetype initialization fails
CVE-2026-53462Medium· 5.9ImageMagick has a Use-After-Free when allocation in CheckPrimitiveExtent fails