Summary
ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow
Advisory details
An integer overflow in the XCF decoder can result in an out of bounds read when a crafted image is read and that can result in a crash.
References
- https://github.com/advisories/GHSA-pjxj-pchx-4c3m
- https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-pjxj-pchx-4c3m
- https://nvd.nist.gov/vuln/detail/CVE-2026-53466
- https://github.com/ImageMagick/ImageMagick/commit/47ca7210515f3c9ea033b86fe4323a70caa74468
- https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-26
- https://github.com/dlemstra/Magick.NET/releases/tag/14.15.0
Related vulnerabilities
All Supply chain →- MEDIUMCVE-2026-61799
netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash
- HIGHCVE-2026-73086
nanoid: Integer Overflow or Wraparound
- HIGHCVE-2026-55764
klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply
- CRITICALCVE-2026-54755
Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token)
- CRITICALCVE-2026-71479
New API: Integer overflow in quota billing yields negative charges (self-crediting)
- HIGHCVE-2026-62897
Microsoft Security Advisory CVE-2026-62897 – .NET Remote Code Execution Vulnerability