
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32636 is a heap-buffer-overflow vulnerability in ImageMagick's NewXMLTree method that can result in an application crash due to an out-of-bounds write of a single zero byte. It affects ImageMagick versions prior to 7.1.2-17 (7.x branch) and prior to 6.9.13-42 (6.x branch), as well as the Magick.NET .NET wrapper prior to version 14.11.0. The vulnerability was reported by researcher "fumfel" and disclosed on March 16, 2026, with the GitHub Advisory Database entry published March 17, 2026. The CVSS v3.1 base score is 5.3 (Moderate) per the GitHub Security Advisory, though Feedly's aggregated data reflects a score of 7.5 (High) from some sources (GitHub Advisory, ImageMagick Advisory).
The root cause is classified as CWE-787 (Out-of-bounds Write): the NewXMLTree method writes a single zero byte past the end of an allocated buffer during XML tree construction, triggering a heap-buffer-overflow condition. The vulnerability is exploitable remotely over the network without authentication or user interaction, as ImageMagick is commonly invoked server-side to process user-supplied image or XML data. No public proof-of-concept exploit code has been identified, but the nature of the bug — a one-byte out-of-bounds null write — typically limits exploitability to denial of service (crash) rather than arbitrary code execution (GitHub Advisory, Red Hat Bugzilla).
Successful exploitation causes ImageMagick to crash, resulting in a denial of service for any application or service that relies on ImageMagick for image or XML processing. There is no known confidentiality or integrity impact — the vulnerability does not expose sensitive data or allow unauthorized modification of data. In environments where ImageMagick processes untrusted input (e.g., web applications accepting image uploads), repeated exploitation could render the image processing pipeline unavailable (GitHub Advisory, ImageMagick Advisory).
Upgrade ImageMagick to version 7.1.2-17 or later (7.x branch) or 6.9.13-42 or later (6.x branch) to remediate the vulnerability. Users of the Magick.NET .NET wrapper should upgrade to version 14.11.0 or later. Red Hat Enterprise Linux 7 Extended Lifecycle Support users can apply the fix via errata RHSA-2026:17618. Ubuntu users should apply USN-8127-1, and openSUSE/SUSE users should apply the relevant security announcements. No configuration-based workarounds have been published; patching is the recommended remediation (ImageMagick Release, Magick.NET Release, Red Hat Bugzilla).
The vulnerability received routine coverage from Linux distribution security teams, with patches issued by Ubuntu (USN-8127-1), Red Hat (RHSA-2026:17618), openSUSE, Debian, and Amazon Linux 2. No notable researcher commentary or significant social media discussion beyond standard vulnerability tracking has been observed. The moderate severity rating and limited impact (DoS only) have kept community reaction subdued (Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."