
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-62946 is an integer overflow vulnerability in ImageMagick's JNX file decoder that causes a heap buffer over-write when processing extremely large JNX files on 32-bit platforms. It affects ImageMagick versions prior to 6.9.13-52 and 7.1.2-27, as well as Magick.NET NuGet packages prior to version 14.15.0. The vulnerability was published by the ImageMagick project on July 15, 2026, with the GitHub Advisory Database entry updated on July 24, 2026. It carries a CVSS v3.1 base score of 5.1 (Moderate) per the GitHub advisory, though NVD assigns it 4.7 (Medium) (GitHub Advisory, Red Hat Bugzilla).
The root cause is an integer overflow or wraparound (CWE-190) in the JNX image decoder. On 32-bit platforms, when ImageMagick processes a specially crafted, extremely large JNX file, an arithmetic calculation overflows the 32-bit integer boundary, resulting in an undersized heap buffer allocation. Subsequent writes to this buffer exceed its bounds, constituting a heap buffer over-write. Exploitation requires the attacker to supply a malicious JNX file to a vulnerable 32-bit ImageMagick build; the vulnerability is not present on 64-bit platforms where larger integer types prevent the overflow condition (GitHub Advisory, GitHub Advisory).
Successful exploitation results in a denial of service (DoS) through application crash or memory corruption on affected 32-bit ImageMagick deployments. The CVSS assessment indicates high availability impact with no confidentiality or integrity impact, meaning attackers cannot directly read or modify data through this vulnerability. The scope is limited to the affected process and does not extend to other system components, and there is no known potential for lateral movement or sensitive data exposure (GitHub Advisory, Red Hat Bugzilla).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-62946. The EPSS score is approximately 0.123% (2nd percentile), indicating a low probability of exploitation in the near term. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained to 32-bit platform builds and requires high attack complexity, further limiting practical risk (GitHub Advisory).
.jnx files or files with JNX MIME types; ImageMagick process crash logs or core dump files generated during image processing.convert, magick, or application processes invoking libMagickCore) when handling JNX files.core, core.<pid>) in the working directory of the ImageMagick process.ImageMagick has released patched versions 6.9.13-52 and 7.1.2-27 that resolve this vulnerability; users should upgrade to these versions or later. For Magick.NET users, upgrading to version 14.15.0 or later addresses the issue. SUSE and openSUSE have issued security updates (SUSE-SU-2026:3414-1) for their distributions. As a workaround where upgrading is not immediately possible, administrators can restrict or disable processing of JNX files, or ensure only 64-bit builds of ImageMagick are deployed, as the vulnerability is specific to 32-bit platforms (GitHub Advisory, SUSE Advisory).
The vulnerability was credited to reporter kongzhenhit-code and disclosed responsibly through GitHub's security advisory process. Red Hat tracked the issue via Bugzilla (Bug 2508878) and classified it as medium severity. SUSE and openSUSE promptly issued security update announcements. No significant social media discussion or notable researcher commentary beyond standard advisory coverage has been observed (Red Hat Bugzilla, SUSE Advisory).
Fix availability across major Linux distributions and their releases.
bookworm
imagemagick
sid
imagemagick: 8:7.1.2.27+dfsg1-1
trixie
imagemagick
bionic (esm-infra)
imagemagick: 8:6.9.7.4+dfsg-16ubuntu6.15+esm16
devel
imagemagick
focal (esm-apps)
imagemagick: 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14
jammy
imagemagick
jammy (esm-apps)
imagemagick: 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14
noble
imagemagick
noble (esm-apps)
imagemagick: 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13
resolute
imagemagick
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."