GHSA-8g9f-ccmr-vfvgMedium· 3.7▾ SunlitDuplicate Advisory: ImageMagick has a possible heap Use After Free vulnerability in its meta coder
▾ Sunlit zone — Low / medium · no exploitation signal
impact 20.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-2gq3-ww97-wfjm. This link is maintained to preserve external references.
ImageMagick before 7.1.2-15 and 6.9.13-40 contains a heap use-after-free in the meta coder: when memory allocation fails, a single byte is written to a stale pointer. Remote attackers can trigger it by processing specially crafted image files, causing a denial of service.
Magick.NET-Q16-AnyCPU < 14.10.3Upgrade to a patched release:
Magick.NET-Q16-AnyCPU 14.10.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-56376Low· 3.7ImageMagick has a possible heap Use After Free vulnerability in its meta coder
GHSA-qvxh-prvr-85w2Low· 3.7ImageMagick: Use-After-Free in FormatMagickCaption when memory allocation fails
CVE-2026-55510Medium· 5.5ImageMagick: Use-After-Free in crafted 8BIM when identifying an image
GHSA-qh5g-q395-cx4jLow· 3.7ImageMagick: Heap-use-after-free via XMP profile could result in a crash
GHSA-6jwg-7q3p-5fqmLow· 3.7ImageMagick: Use-After-Free when freetype initialization fails
CVE-2026-53462Medium· 5.9ImageMagick has a Use-After-Free when allocation in CheckPrimitiveExtent fails