
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-62946 is an integer overflow vulnerability in the JNX decoder of ImageMagick that causes a heap buffer over-write when processing extremely large JNX files on 32-bit platforms. It affects ImageMagick versions prior to 7.1.2-27 and 6.9.13-52, as well as Magick.NET NuGet packages prior to version 14.15.0. The vulnerability was reported by researcher kongzhenhit-code, published by maintainer dlemstra on July 15, 2026, and added to the GitHub Advisory Database on July 24, 2026. It carries a CVSS v3.1 base score of 5.1 (Moderate) (GitHub Advisory, ImageMagick Advisory).
The root cause is an integer overflow or wraparound (CWE-190) in ImageMagick's JNX file decoder. On 32-bit platforms, when processing an extremely large JNX file, an arithmetic calculation overflows the bounds of the integer type used, resulting in an incorrect (smaller or negative) value being used for a heap buffer allocation or indexing operation, ultimately causing a heap buffer over-write. The attack vector is local (AV:L) with high attack complexity (AC:H), meaning an attacker must be able to supply a specially crafted JNX file to the vulnerable application and the exploit is constrained to 32-bit build environments. No privileges are required and no user interaction is needed beyond the application processing the malicious file (GitHub Advisory, ImageMagick Advisory).
Successful exploitation results in a heap buffer over-write, which can crash the ImageMagick process and cause a denial of service (high availability impact). The CVSS assessment indicates no confidentiality or integrity impact, meaning data exfiltration or code execution are not the primary expected outcomes under typical conditions. The vulnerability is limited in scope to 32-bit builds of ImageMagick and Magick.NET, reducing the breadth of affected deployments (GitHub Advisory, ImageMagick Advisory).
Users should upgrade to the patched versions of ImageMagick (7.1.2-27 or 6.9.13-52) or Magick.NET (14.15.0 or later) to remediate this vulnerability. For Magick.NET NuGet packages, all affected variants (Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-x86, Magick.NET-Q16-x86, Magick.NET-Q8-AnyCPU, Magick.NET-Q8-x86) should be updated to version 14.15.0. As a workaround, organizations can restrict processing of JNX files via ImageMagick policy configuration or avoid deploying 32-bit builds where possible (ImageMagick Advisory, Magick.NET Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."