
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28690 is a stack-based buffer overflow vulnerability in the MNG encoder of ImageMagick, a widely used open-source image editing library. The flaw stems from missing bounds checks in the MNG encoder that allow attacker-controlled data to corrupt the stack. It affects ImageMagick versions prior to 7.1.2-16 (7.x branch) and prior to 6.9.13-41 (6.9.x branch), as well as Magick.NET NuGet packages prior to version 14.10.4. The vulnerability was published on March 9–10, 2026, and carries a CVSS v3.1 base score of 6.9 (Medium/Moderate) (GitHub Advisory, Github Advisory DB).
The vulnerability is classified as CWE-121 (Stack-based Buffer Overflow) and resides in ImageMagick's MNG (Multiple-image Network Graphics) encoder component. Missing bounds checks during MNG encoding allow a write of attacker-controlled data beyond the bounds of a stack-allocated buffer, as confirmed by an AddressSanitizer report showing a WRITE of size 1 at an out-of-bounds stack address (0x7ffec4971310). Exploitation requires local access and high attack complexity — an attacker must supply a crafted MNG image file to trigger the overflow during encoding. The vulnerability was discovered and reported by researcher zerojackyi (GitHub Advisory, Github Advisory DB).
Successful exploitation can corrupt stack memory with attacker-controlled data, leading to high integrity and availability impacts — including unauthorized data modification and application crashes (denial of service). A limited confidentiality impact is also possible through potential information disclosure from corrupted stack contents. The scope is unchanged, meaning the impact is confined to the vulnerable ImageMagick process itself, limiting lateral movement potential (GitHub Advisory).
Users should upgrade ImageMagick to version 7.1.2-16 or later (7.x branch) or 6.9.13-41 or later (6.9.x branch). Magick.NET NuGet package users should upgrade to version 14.10.4 or later. As interim workarounds for systems that cannot be immediately patched, restrict local access to systems running vulnerable ImageMagick versions, avoid processing untrusted MNG image files, and consider disabling MNG format support in ImageMagick's policy configuration if not operationally required. Distribution-specific patches have been issued for Debian, SUSE/openSUSE, and Amazon Linux 2 (GitHub Advisory, Github Advisory DB).
The vulnerability was disclosed by ImageMagick maintainer dlemstra via a GitHub Security Advisory on March 9, 2026, with credit to reporter zerojackyi. Multiple Linux distributions including Debian, SUSE/openSUSE, and Amazon Linux 2 have issued security advisories and updated packages. Security scanning vendors Tenable (Nessus) and Qualys have added detection plugins for this CVE. Coverage has been noted on Linux security news aggregators and community forums, though no significant broader media or researcher commentary has emerged given the moderate severity and limited exploitability (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."