CVE-2026-28494
C# vulnerability analysis and mitigation

Overview

CVE-2026-28494 is a stack-based buffer overflow vulnerability in ImageMagick's morphology kernel parsing functions, allowing an attacker to cause stack corruption by supplying maliciously crafted kernel strings. It affects ImageMagick versions prior to 6.9.13-41 and 7.0.0-0 through 7.1.2-16, as well as Magick.NET NuGet packages prior to version 14.10.4. The vulnerability was published on March 9, 2026, and assigned a CVSS v3.1 base score of 7.1 (High) (GitHub Advisory, Red Hat).

Technical details

The root cause is classified as CWE-120 (Buffer Copy without Checking Size of Input) and CWE-121 (Stack-based Buffer Overflow). In ImageMagick's morphology kernel parsing code, user-controlled kernel strings that exceed a buffer boundary are copied into fixed-size stack buffers using memcpy without any bounds checking, resulting in stack corruption. Exploitation requires local access and user interaction — for example, a victim must process a maliciously crafted image or kernel string with a vulnerable ImageMagick version. No public proof-of-concept exploit code has been identified (GitHub Advisory, Red Hat Bugzilla).

Impact

Successful exploitation can lead to arbitrary code execution or denial of service (DoS), impacting both system integrity and availability. An attacker who triggers the overflow can corrupt the call stack, potentially redirecting execution flow to attacker-controlled code running with the privileges of the ImageMagick process. Confidentiality is not directly impacted per the CVSS scoring, but integrity and availability are rated High (GitHub Advisory, Red Hat).

Mitigation and workarounds

Users should upgrade ImageMagick to version 7.1.2-16 or later (7.x branch) or 6.9.13-41 or later (6.9.x branch). For Magick.NET NuGet users, upgrading to version 14.10.4 or later addresses the vulnerability. Until patching is possible, restrict processing of untrusted image files and limit user access to ImageMagick functionality. Distribution-specific updates are available for Debian, SUSE/openSUSE, and Amazon Linux 2 (GitHub Advisory, Red Hat).

Community reactions

The vulnerability was disclosed by ImageMagick maintainer dlemstra via a GitHub Security Advisory on March 9, 2026. Red Hat tracked the issue via Bugzilla (Bug 2445901) and published a CVE advisory. Multiple Linux distributions including Debian, SUSE/openSUSE, and Amazon Linux 2 subsequently issued security updates. Vulnerability scanners from Tenable (Nessus) and Qualys added detection plugins shortly after disclosure (Red Hat Bugzilla, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related C# vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-p5rm-jg5c-8c77MEDIUM6.1
  • C# logoC#
  • Microsoft.OpenApi.Kiota
NoYesJul 24, 2026
CVE-2026-62946MEDIUM5.1
  • C# logoC#
  • Magick.NET-Q16-AnyCPU
NoYesJul 24, 2026
CVE-2026-62363MEDIUM5
  • C# logoC#
  • Magick.NET-Q16-HDRI-OpenMP-arm64
NoYesJul 24, 2026
CVE-2026-62343MEDIUM4.7
  • C# logoC#
  • Magick.NET-Q16-OpenMP-arm64
NoYesJul 24, 2026
GHSA-464c-974j-9xm6LOW3.3
  • JavaScript logoJavaScript
  • @aws-cdk/aws-codebuild
NoYesJul 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management