Launch Week Day 1: Announcing Security Design Review
MEDIUM 4.0 NuGet

ImageMagick: Heap Buffer Over-read in WaveletDenoise when processing small images

GHSA-qpgx-jfcq-r59f · CVE-2026-27798

Published · Modified

Description

A heap buffer over-read vulnerability occurs when processing an image with small dimension using the -wavelet-denoise operator.

==3693336==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x511000001280 at pc 0x5602c8b0cc75 bp 0x7ffcb105d510 sp 0x7ffcb105d500
READ of size 4 at 0x511000001280 thread T0

Ready to move

Start Securing

Free, no credit card | First findings in minutes