GHSA-rvhp-75f6-9jqhLow· 3.3▾ SunlitImageMagick: Policy Bypass possible with matrix-backed operations
▾ Sunlit zone — Low / medium · no exploitation signal
impact 18.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Matrix bases operations like -canny are missing a check for allowed memory allocation that could result allocating more memory than allowed.
Magick.NET-Q16-AnyCPU < 14.15.0Magick.NET-Q16-HDRI-AnyCPU < 14.15.0Magick.NET-Q16-HDRI-OpenMP-arm64 < 14.15.0Magick.NET-Q16-HDRI-x64 < 14.15.0Magick.NET-Q16-HDRI-x86 < 14.15.0Magick.NET-Q16-OpenMP-arm64 < 14.15.0Magick.NET-Q16-OpenMP-x64 < 14.15.0Magick.NET-Q16-arm64 < 14.15.0Magick.NET-Q16-x64 < 14.15.0Magick.NET-Q16-x86 < 14.15.0Magick.NET-Q8-AnyCPU < 14.15.0Magick.NET-Q8-OpenMP-arm64 < 14.15.0Magick.NET-Q8-OpenMP-x64 < 14.15.0Magick.NET-Q8-arm64 < 14.15.0Magick.NET-Q8-x64 < 14.15.0Magick.NET-Q8-x86 < 14.15.0Magick.NET-Q16-HDRI-arm64 < 14.15.0Upgrade to a patched release:
Magick.NET-Q16-AnyCPU 14.15.0Magick.NET-Q16-HDRI-AnyCPU 14.15.0Magick.NET-Q16-HDRI-OpenMP-arm64 14.15.0Magick.NET-Q16-HDRI-x64 14.15.0Magick.NET-Q16-HDRI-x86 14.15.0Magick.NET-Q16-OpenMP-arm64 14.15.0Magick.NET-Q16-OpenMP-x64 14.15.0Magick.NET-Q16-arm64 14.15.0Magick.NET-Q16-x64 14.15.0Magick.NET-Q16-x86 14.15.0Magick.NET-Q8-AnyCPU 14.15.0Magick.NET-Q8-OpenMP-arm64 14.15.0Magick.NET-Q8-OpenMP-x64 14.15.0Magick.NET-Q8-arm64 14.15.0Magick.NET-Q8-x64 14.15.0Magick.NET-Q8-x86 14.15.0Magick.NET-Q16-HDRI-arm64 14.15.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55594Medium· 5.3ImageMagick: Stack Overflow in MVG decoder due to missing depth check.
CVE-2026-55595Medium· 4.7ImageMagick: Infinite Loop in connected-components when providing invalid arguments
GHSA-qh5g-q395-cx4jLow· 3.7ImageMagick: Heap-use-after-free via XMP profile could result in a crash
GHSA-vghg-5jrg-2398Low· 3.3ImageMagick: Policy Bypass in script operation due to missing checks
GHSA-cvhv-g4rq-3hmwLow· 3.3ImageMagick: Memory Leak when providing invalid options to the cli
CVE-2026-53466Medium· 6.5ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow