
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-62343 is a heap buffer over-write vulnerability in ImageMagick affecting its morphology operation when an invalid, user-supplied kernel is provided. It affects ImageMagick versions prior to 6.9.13-51 and versions 7.0.1-0 through 7.1.2-26 (exclusive), as well as Magick.NET NuGet packages prior to 14.15.0. The vulnerability was published on July 14, 2026, and added to the GitHub Advisory Database on July 24, 2026. It carries a CVSS v3.1 base score of 4.7 (Medium) (Github Advisory, Red Hat Bugzilla).
The root cause is an integer overflow or wraparound (CWE-190) combined with buffer access with an incorrect length value (CWE-805), which together lead to an out-of-bounds write (CWE-787) on the heap. When ImageMagick processes a morphology operation using a user-supplied kernel, insufficient validation of kernel parameters allows an integer overflow to produce an incorrect buffer size, resulting in a heap buffer over-write. Exploitation requires local access and user interaction — specifically, a victim must open or process a crafted image or kernel file. The vulnerability was reported by researcher Kwstubbs (Github Advisory, Github Advisory).
Successful exploitation results in a denial of service (DoS) through a heap buffer over-write, causing the ImageMagick process to crash. There is no impact on confidentiality or data integrity — only availability is affected. The scope is limited to the vulnerable component itself, with no lateral movement potential identified (Github Advisory, Red Hat Bugzilla).
There is no known public proof-of-concept exploit code or evidence of in-the-wild exploitation as of the time of writing. The EPSS score is approximately 0.124% (3rd percentile), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable (Github Advisory).
Users should upgrade ImageMagick to version 6.9.13-51 or 7.1.2-26 (or later) to remediate this vulnerability. For users of the Magick.NET NuGet packages, upgrading to version 14.15.0 or later is required. SUSE and openSUSE have issued security updates (SUSE-SU-2026:3414-1) for their distributions. No configuration-based workarounds have been published; patching is the recommended remediation (Github Advisory, Red Hat Bugzilla).
Red Hat has tracked this vulnerability via Bugzilla (Bug 2508793) and assigned it medium priority and severity. SUSE issued a security update (SUSE-SU-2026:3414-1) addressing this and related ImageMagick issues. No notable researcher commentary or significant social media discussion has been identified beyond standard vulnerability tracking (Red Hat Bugzilla).
Fix availability across major Linux distributions and their releases.
bookworm
imagemagick
sid
imagemagick: 8:7.1.2.26+dfsg1-1
trixie
imagemagick
bionic (esm-infra)
imagemagick
devel
imagemagick
focal (esm-apps)
imagemagick
jammy
imagemagick
jammy (esm-apps)
imagemagick
noble
imagemagick
noble (esm-apps)
imagemagick
resolute
imagemagick
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."