Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.5 NuGet

ImageMagick has Heap Out-of-Bounds Read in DCM Decoder (ReadDCMImage)

GHSA-pmq6-8289-hx3v · CVE-2026-25982

Published · Modified

Description

A heap out-of-bounds read vulnerability exists in the coders/dcm.c module. When processing DICOM files with a specific configuration, the decoder loop incorrectly reads bytes per iteration. This causes the function to read past the end of the allocated buffer, potentially leading to a Denial of Service (crash) or Information Disclosure (leaking heap memory into the image).

Ready to move

Start Securing

Free, no credit card | First findings in minutes