
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28693 is an integer overflow vulnerability in the DIB (Device Independent Bitmap) coder component of ImageMagick, a widely used open-source image editing library. The flaw can result in out-of-bounds read or write conditions when processing a specially crafted image file, potentially enabling arbitrary code execution, privilege escalation, information disclosure, or Denial of Service. It affects ImageMagick versions prior to 7.1.2-16 (7.x branch) and prior to 6.9.13-41 (6.x branch), as well as Magick.NET NuGet packages prior to version 14.10.4. The vulnerability was published on March 9, 2026, and carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, Red Hat).
The root cause is an integer overflow or wraparound (CWE-190) in the DIB coder component of ImageMagick, which subsequently leads to out-of-bounds read (CWE-125) or out-of-bounds write (CWE-787) conditions in memory. An attacker can exploit this by supplying a maliciously crafted DIB/BMP image file to an ImageMagick instance, causing arithmetic calculations on image dimensions or buffer sizes to overflow and produce incorrect allocation or access sizes. No privileges or user interaction are required, but the attack complexity is rated High, indicating that specific conditions or race conditions may need to be met for reliable exploitation. The vulnerability was credited to researcher jakelodwick (GitHub Advisory, Red Hat Bugzilla).
Successful exploitation can result in arbitrary code execution, privilege escalation, sensitive information disclosure, or a Denial of Service condition on systems running vulnerable ImageMagick versions. All three security dimensions — confidentiality, integrity, and availability — are rated High, meaning an attacker could fully compromise the affected process, read or corrupt memory contents, or crash the application. Systems that automatically process user-supplied images (e.g., web applications, media pipelines) are at elevated risk, as exploitation could serve as an entry point for lateral movement within a network (GitHub Advisory, Red Hat).
Upgrade ImageMagick to version 7.1.2-16 or later (7.x branch) or 6.9.13-41 or later (6.x branch). For .NET users, upgrade Magick.NET NuGet packages to version 14.10.4 or later. Red Hat Enterprise Linux 7 Extended Lifecycle Support users should apply errata RHSA-2026:6713. As a workaround where patching is not immediately possible, consider disabling DIB/BMP format support in ImageMagick's policy.xml, restricting network-accessible image processing services, and implementing input validation to reject untrusted image files (GitHub Advisory, Red Hat Bugzilla, Red Hat Errata).
The vulnerability received standard coverage across Linux distribution security channels, with Debian, SUSE, openSUSE, and Amazon Linux issuing advisories and updated packages. Tenable published multiple Nessus detection plugins (e.g., 304613, 305089, 305282, 307507, 307663, 309923, 319668) to identify vulnerable systems. Community discussion was limited, with brief mentions on Bluesky and security aggregator sites, reflecting the absence of active exploitation (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."