CVE-2026-31853
C# vulnerability analysis and mitigation

Overview

CVE-2026-31853 is a heap-based buffer overflow vulnerability in ImageMagick's SFW (Seattle FilmWorks) decoder that affects only 32-bit system builds. When processing extremely large images, an integer overflow condition triggers a heap buffer over-write, causing a crash (denial of service). The vulnerability affects ImageMagick versions prior to 7.1.2-16 and 6.9.13-41, as well as Magick.NET NuGet packages prior to version 14.10.4. It was published on March 10, 2026, and has a CVSS v3.1 base score of 5.5 (Medium) per NVD, or 5.7 (Moderate) per the GitHub Advisory (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is a CWE-122 (Heap-based Buffer Overflow) triggered by an integer overflow on 32-bit systems during SFW image decoding. On 32-bit architectures, size calculations for extremely large images can overflow, resulting in an undersized heap buffer allocation that is subsequently overwritten with image data. The attack vector is local (AV:L), requires no privileges (PR:N), and has high attack complexity (AC:H), as the attacker must supply a specially crafted, extremely large SFW image file to a vulnerable 32-bit ImageMagick process. The vulnerability was reported by researcher Mcsky23 (GitHub Advisory).

Impact

Successful exploitation primarily results in a denial of service via application crash, as the heap buffer over-write causes ImageMagick to terminate abnormally when processing the malicious image. There is a low integrity impact (minor data modification potential) and no confidentiality impact, meaning sensitive data exposure is not a direct concern. The scope is limited to the affected ImageMagick process on 32-bit systems, with no lateral movement potential inherent to this vulnerability (GitHub Advisory, Red Hat Bugzilla).

Mitigation and workarounds

ImageMagick has released fixed versions 7.1.2-16 and 6.9.13-41 that address this vulnerability. For Magick.NET NuGet package users, upgrading to version 14.10.4 or later is required. Downstream Linux distributions including Debian, SUSE/openSUSE, and Amazon Linux 2 have issued updated packages. As a workaround where upgrading is not immediately possible, restricting processing of SFW image files or avoiding use of 32-bit ImageMagick builds can mitigate exposure (GitHub Advisory, Red Hat Bugzilla).

Community reactions

The vulnerability received routine coverage across Linux security advisory channels, with Debian, SUSE, openSUSE, and Amazon Linux all issuing security updates. Tenable published multiple Nessus detection plugins (e.g., 304613, 305282, 305289, 307507) and Qualys added detection signatures. No notable researcher commentary or significant social media discussion beyond automated CVE notification accounts has been observed (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related C# vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-p5rm-jg5c-8c77MEDIUM6.1
  • C# logoC#
  • Microsoft.OpenApi.Kiota
NoYesJul 24, 2026
CVE-2026-62946MEDIUM5.1
  • C# logoC#
  • Magick.NET-Q8-x86
NoYesJul 24, 2026
CVE-2026-62363MEDIUM5
  • C# logoC#
  • Magick.NET-Q8-AnyCPU
NoYesJul 24, 2026
CVE-2026-62343MEDIUM4.7
  • C# logoC#
  • Magick.NET-Q8-x86
NoYesJul 24, 2026
GHSA-464c-974j-9xm6LOW3.3
  • JavaScript logoJavaScript
  • @aws-cdk/aws-codebuild
NoYesJul 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management