CVE-2026-28690
C# vulnerability analysis and mitigation

Overview

CVE-2026-28690 is a stack-based buffer overflow vulnerability in the MNG encoder of ImageMagick, a widely used open-source image editing library. The flaw stems from missing bounds checks in the MNG encoder that allow attacker-controlled data to corrupt the stack. It affects ImageMagick versions prior to 7.1.2-16 (7.x branch) and prior to 6.9.13-41 (6.9.x branch), as well as Magick.NET NuGet packages prior to version 14.10.4. The vulnerability was published on March 9–10, 2026, and carries a CVSS v3.1 base score of 6.9 (Medium/Moderate) (GitHub Advisory, Github Advisory DB).

Technical details

The vulnerability is classified as CWE-121 (Stack-based Buffer Overflow) and resides in ImageMagick's MNG (Multiple-image Network Graphics) encoder component. Missing bounds checks during MNG encoding allow a write of attacker-controlled data beyond the bounds of a stack-allocated buffer, as confirmed by an AddressSanitizer report showing a WRITE of size 1 at an out-of-bounds stack address (0x7ffec4971310). Exploitation requires local access and high attack complexity — an attacker must supply a crafted MNG image file to trigger the overflow during encoding. The vulnerability was discovered and reported by researcher zerojackyi (GitHub Advisory, Github Advisory DB).

Impact

Successful exploitation can corrupt stack memory with attacker-controlled data, leading to high integrity and availability impacts — including unauthorized data modification and application crashes (denial of service). A limited confidentiality impact is also possible through potential information disclosure from corrupted stack contents. The scope is unchanged, meaning the impact is confined to the vulnerable ImageMagick process itself, limiting lateral movement potential (GitHub Advisory).

Mitigation and workarounds

Users should upgrade ImageMagick to version 7.1.2-16 or later (7.x branch) or 6.9.13-41 or later (6.9.x branch). Magick.NET NuGet package users should upgrade to version 14.10.4 or later. As interim workarounds for systems that cannot be immediately patched, restrict local access to systems running vulnerable ImageMagick versions, avoid processing untrusted MNG image files, and consider disabling MNG format support in ImageMagick's policy configuration if not operationally required. Distribution-specific patches have been issued for Debian, SUSE/openSUSE, and Amazon Linux 2 (GitHub Advisory, Github Advisory DB).

Community reactions

The vulnerability was disclosed by ImageMagick maintainer dlemstra via a GitHub Security Advisory on March 9, 2026, with credit to reporter zerojackyi. Multiple Linux distributions including Debian, SUSE/openSUSE, and Amazon Linux 2 have issued security advisories and updated packages. Security scanning vendors Tenable (Nessus) and Qualys have added detection plugins for this CVE. Coverage has been noted on Linux security news aggregators and community forums, though no significant broader media or researcher commentary has emerged given the moderate severity and limited exploitability (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related C# vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-p5rm-jg5c-8c77MEDIUM6.1
  • C# logoC#
  • Microsoft.OpenApi.Kiota
NoYesJul 24, 2026
CVE-2026-62946MEDIUM5.1
  • C# logoC#
  • Magick.NET-Q16-AnyCPU
NoYesJul 24, 2026
CVE-2026-62363MEDIUM5
  • C# logoC#
  • Magick.NET-Q16-HDRI-OpenMP-arm64
NoYesJul 24, 2026
CVE-2026-62343MEDIUM4.7
  • C# logoC#
  • Magick.NET-Q16-OpenMP-arm64
NoYesJul 24, 2026
GHSA-464c-974j-9xm6LOW3.3
  • JavaScript logoJavaScript
  • @aws-cdk/aws-codebuild
NoYesJul 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management