CVE-2025-66628
C# vulnerability analysis and mitigation

ImageMagick is a software suite to create, edit, compose, or convert bitmap images. In versions 7.1.2-9 and prior, the TIM (PSX TIM) image parser contains a critical integer overflow vulnerability in its ReadTIMImage function (coders/tim.c). The code reads width and height (16-bit values) from the file header and calculates image_size = 2 * width * height without checking for overflow. On 32-bit systems (or where size_t is 32-bit), this calculation can overflow if width and height are large (e.g., 65535), wrapping around to a small value. This results in a small heap allocation via AcquireQuantumMemory and later operations relying on the dimensions can trigger an out of bounds read. This issue is fixed in version 7.1.2-10.


SourceNVD

Related C# vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-40324CRITICAL9.1
  • C#C#
  • HotChocolate.Language
NoYesApr 18, 2026
GHSA-9j88-vvj5-vhgrMEDIUM6.5
  • C#C#
  • MailKit
NoYesApr 18, 2026
CVE-2026-41319MEDIUM6.5
  • C#C#
  • MailKit
NoYesApr 18, 2026
CVE-2026-41078MEDIUM5.9
  • C#C#
  • OpenTelemetry.Exporter.Jaeger
NoNoApr 18, 2026
GHSA-h39g-6x3c-7fq9LOW3.8
  • C#C#
  • Zio
NoYesApr 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management