Magick has 44 CVEs on record. Disclosure cadence is accelerating: 43 in the last 90 days against 1 in the 90 before. The busiest recent month was July 2026 with 30. The median CVSS is 4.5 (medium). None have a confirmed exploitation report. The dominant weakness classes are CWE-401 (12) and CWE-787 (6).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 4.5
- Publish → KEV
- —
- Last 90 days
- 43 prev 1
Weakness classes
Products
- Magick.NET-Q16-AnyCPU 44
Worst active — by depth score
CVE-2026-53461High· 7.5ImageMagick has out-of-bounds write in ICON decoder due to incorrect loop41CVE-2026-53460High· 7.5ImageMagick: Policy Bypass can Trigger an Out-of-Memory condition41CVE-2026-49218High· 7.5ImageMagick: Policy Bypass in DCM decoder could result in image with invalid dimensions41CVE-2026-53466Medium· 6.5ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow36CVE-2026-55628Medium· 6.1ImageMagick: Policy Bypass in concatenate operation due to missing checks34
Magick vulnerabilities
CVEs affecting Magick, newest first. Open any entry for full detail, references, and exploit status.
44 CVEsRSS
CVE-2026-53467Medium· 5.3ImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchanged
ImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchanged
CVE-2026-53463Medium· 4.3ImageMagick has Null Pointer Dereference caused by the distort operation when passing incorrect arguments
ImageMagick has Null Pointer Dereference caused by the distort operation when passing incorrect arguments
CVE-2026-53464Medium· 4.0ImageMagick: Memory Leak in wand option parser when providing invalid arguments
ImageMagick: Memory Leak in wand option parser when providing invalid arguments
CVE-2026-53465Medium· 6.2ImageMagick has a Heap Buffer Over-Write in SF3 encoder when writing multi-frame image
ImageMagick has a Heap Buffer Over-Write in SF3 encoder when writing multi-frame image
CVE-2026-53462Medium· 5.9ImageMagick has a Use-After-Free when allocation in CheckPrimitiveExtent fails
ImageMagick has a Use-After-Free when allocation in CheckPrimitiveExtent fails
CVE-2026-48724Medium· 5.5ImageMagick has a Heap Buffer Underwrite in the Floyd-Steinberg depth dithering method
ImageMagick has a Heap Buffer Underwrite in the Floyd-Steinberg depth dithering method
CVE-2026-48733Medium· 4.7ImageMagick has an Infinite Loop in subimage-search with crafted image
ImageMagick has an Infinite Loop in subimage-search with crafted image
CVE-2026-48734Medium· 5.5ImageMagick Vulnerable to Stack Overflow in its MVG Decoder
ImageMagick Vulnerable to Stack Overflow in its MVG Decoder
CVE-2026-48994Medium· 5.9ImageMagick has a Heap Buffer Over-Write in MAT decoder on 32-bit systems
ImageMagick has a Heap Buffer Over-Write in MAT decoder on 32-bit systems
CVE-2026-49218High· 7.5ImageMagick: Policy Bypass in DCM decoder could result in image with invalid dimensions
ImageMagick: Policy Bypass in DCM decoder could result in image with invalid dimensions
CVE-2026-49219Medium· 5.5ImageMagick: Policy Bypass can read disallowed files via symlink
ImageMagick: Policy Bypass can read disallowed files via symlink
CVE-2026-53460High· 7.5ImageMagick: Policy Bypass can Trigger an Out-of-Memory condition
ImageMagick: Policy Bypass can Trigger an Out-of-Memory condition
CVE-2026-53461High· 7.5ImageMagick has out-of-bounds write in ICON decoder due to incorrect loop
ImageMagick has out-of-bounds write in ICON decoder due to incorrect loop
CVE-2026-56370Low· 3.3ImageMagick has out-of-bounds access in ConnectedComponentsImage() via CLI-controlled connected-components:* artifacts
ImageMagick has out-of-bounds access in ConnectedComponentsImage() via CLI-controlled connected-components:* artifacts