Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.5 NuGet

ImageMagick: Heap overflow in pcd decoder leads to out of bounds read.

GHSA-wrhr-rf8j-r842 · CVE-2026-26284

Published · Modified

Description

The pcd coder lacks proper boundary checking when processing Huffman-coded data. The decoder contains an function that has an incorrect initialization that could cause an out of bounds read.

==3900053==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x502000003c6c at pc 0x55601b9cc552 bp 0x7ffd904b1f70 sp 0x7ffd904b1f60
READ of size 1 at 0x502000003c6c thread T0

Ready to move

Start Securing

Free, no credit card | First findings in minutes