
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28494 is a stack-based buffer overflow vulnerability in ImageMagick's morphology kernel parsing functions, allowing an attacker to cause stack corruption by supplying maliciously crafted kernel strings. It affects ImageMagick versions prior to 6.9.13-41 and 7.0.0-0 through 7.1.2-16, as well as Magick.NET NuGet packages prior to version 14.10.4. The vulnerability was published on March 9, 2026, and assigned a CVSS v3.1 base score of 7.1 (High) (GitHub Advisory, Red Hat).
The root cause is classified as CWE-120 (Buffer Copy without Checking Size of Input) and CWE-121 (Stack-based Buffer Overflow). In ImageMagick's morphology kernel parsing code, user-controlled kernel strings that exceed a buffer boundary are copied into fixed-size stack buffers using memcpy without any bounds checking, resulting in stack corruption. Exploitation requires local access and user interaction — for example, a victim must process a maliciously crafted image or kernel string with a vulnerable ImageMagick version. No public proof-of-concept exploit code has been identified (GitHub Advisory, Red Hat Bugzilla).
Successful exploitation can lead to arbitrary code execution or denial of service (DoS), impacting both system integrity and availability. An attacker who triggers the overflow can corrupt the call stack, potentially redirecting execution flow to attacker-controlled code running with the privileges of the ImageMagick process. Confidentiality is not directly impacted per the CVSS scoring, but integrity and availability are rated High (GitHub Advisory, Red Hat).
Users should upgrade ImageMagick to version 7.1.2-16 or later (7.x branch) or 6.9.13-41 or later (6.9.x branch). For Magick.NET NuGet users, upgrading to version 14.10.4 or later addresses the vulnerability. Until patching is possible, restrict processing of untrusted image files and limit user access to ImageMagick functionality. Distribution-specific updates are available for Debian, SUSE/openSUSE, and Amazon Linux 2 (GitHub Advisory, Red Hat).
The vulnerability was disclosed by ImageMagick maintainer dlemstra via a GitHub Security Advisory on March 9, 2026. Red Hat tracked the issue via Bugzilla (Bug 2445901) and published a CVE advisory. Multiple Linux distributions including Debian, SUSE/openSUSE, and Amazon Linux 2 subsequently issued security updates. Vulnerability scanners from Tenable (Nessus) and Qualys added detection plugins shortly after disclosure (Red Hat Bugzilla, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."