CVE-2026-33536
C# vulnerability analysis and mitigation

Overview

CVE-2026-33536 is a stack-based buffer overflow vulnerability in ImageMagick's InterpretImageFilename function that can result in an out-of-bounds write to stack memory. It was disclosed on March 24, 2026 by researcher "fumfel" via the ImageMagick GitHub security advisory (GHSA-8793-7xv6-82cf) and published to the NVD on March 26, 2026. Affected versions include ImageMagick before 7.1.2-18 and before 6.9.13-43, as well as Magick.NET NuGet packages before 14.11.1. The vulnerability carries a CVSS v3.1 base score of 5.1 (Moderate) (GitHub Advisory, Github Advisory DB).

Technical details

The root cause is an incorrect return value handling on certain platforms within the InterpretImageFilename function, causing a pointer to be incremented past the end of a stack-allocated buffer (CWE-121: Stack-based Buffer Overflow; CWE-787: Out-of-bounds Write). The flaw results in a single-byte write beyond the buffer boundary, as confirmed by AddressSanitizer output showing a WRITE of size 1 at an address beyond the stack buffer. The attack vector is local, requires no privileges, but has high attack complexity, limiting practical exploitability. No public proof-of-concept exploit code has been identified (GitHub Advisory, Github Advisory DB).

Impact

Successful exploitation of this vulnerability can cause a denial of service (application crash) due to memory corruption on the stack. The impact is limited to availability — there is no confidentiality or integrity impact identified. Because the attack vector is local and attack complexity is high, the practical risk of widespread exploitation is low, and there is no evidence of lateral movement potential or sensitive data exposure associated with this vulnerability (GitHub Advisory).

Mitigation and workarounds

Users should upgrade ImageMagick to version 7.1.2-18 or later (for the 7.x branch) or 6.9.13-43 or later (for the 6.x branch). Magick.NET NuGet package users should upgrade to version 14.11.1 or later. No configuration-based workarounds have been published; upgrading to a patched release is the recommended remediation. Linux distribution users (SUSE, Debian, Amazon Linux) should apply vendor-provided security updates as they become available (GitHub Advisory, Github Advisory DB).

Community reactions

The vulnerability was reported by researcher "fumfel" and patched by ImageMagick maintainer "dlemstra." Multiple Linux distributions including SUSE, Debian, and Amazon Linux have issued security advisories and package updates addressing this CVE. No significant social media discussion or notable researcher commentary beyond the standard advisory process has been identified (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related C# vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-p5rm-jg5c-8c77MEDIUM6.1
  • C# logoC#
  • Microsoft.OpenApi.Kiota
NoYesJul 24, 2026
CVE-2026-62946MEDIUM5.1
  • C# logoC#
  • Magick.NET-Q8-x86
NoYesJul 24, 2026
CVE-2026-62363MEDIUM5
  • C# logoC#
  • Magick.NET-Q8-AnyCPU
NoYesJul 24, 2026
CVE-2026-62343MEDIUM4.7
  • C# logoC#
  • Magick.NET-Q8-x86
NoYesJul 24, 2026
GHSA-464c-974j-9xm6LOW3.3
  • JavaScript logoJavaScript
  • @aws-cdk/aws-codebuild
NoYesJul 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management