
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-31853 is a heap-based buffer overflow vulnerability in ImageMagick's SFW (Seattle FilmWorks) decoder that affects only 32-bit system builds. When processing extremely large images, an integer overflow condition triggers a heap buffer over-write, causing a crash (denial of service). The vulnerability affects ImageMagick versions prior to 7.1.2-16 and 6.9.13-41, as well as Magick.NET NuGet packages prior to version 14.10.4. It was published on March 10, 2026, and has a CVSS v3.1 base score of 5.5 (Medium) per NVD, or 5.7 (Moderate) per the GitHub Advisory (GitHub Advisory, Red Hat Bugzilla).
The root cause is a CWE-122 (Heap-based Buffer Overflow) triggered by an integer overflow on 32-bit systems during SFW image decoding. On 32-bit architectures, size calculations for extremely large images can overflow, resulting in an undersized heap buffer allocation that is subsequently overwritten with image data. The attack vector is local (AV:L), requires no privileges (PR:N), and has high attack complexity (AC:H), as the attacker must supply a specially crafted, extremely large SFW image file to a vulnerable 32-bit ImageMagick process. The vulnerability was reported by researcher Mcsky23 (GitHub Advisory).
Successful exploitation primarily results in a denial of service via application crash, as the heap buffer over-write causes ImageMagick to terminate abnormally when processing the malicious image. There is a low integrity impact (minor data modification potential) and no confidentiality impact, meaning sensitive data exposure is not a direct concern. The scope is limited to the affected ImageMagick process on 32-bit systems, with no lateral movement potential inherent to this vulnerability (GitHub Advisory, Red Hat Bugzilla).
ImageMagick has released fixed versions 7.1.2-16 and 6.9.13-41 that address this vulnerability. For Magick.NET NuGet package users, upgrading to version 14.10.4 or later is required. Downstream Linux distributions including Debian, SUSE/openSUSE, and Amazon Linux 2 have issued updated packages. As a workaround where upgrading is not immediately possible, restricting processing of SFW image files or avoiding use of 32-bit ImageMagick builds can mitigate exposure (GitHub Advisory, Red Hat Bugzilla).
The vulnerability received routine coverage across Linux security advisory channels, with Debian, SUSE, openSUSE, and Amazon Linux all issuing security updates. Tenable published multiple Nessus detection plugins (e.g., 304613, 305282, 305289, 307507) and Qualys added detection signatures. No notable researcher commentary or significant social media discussion beyond automated CVE notification accounts has been observed (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."