Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.9 NuGet

ImageMagick has stack write buffer overflow in MNG encoder

GHSA-7h7q-j33q-hvpf · CVE-2026-28690

Published · Modified

Description

A stack buffer overflow vulnerability exists in the MNG encoder. There is a bounds checks missing that could corrupting the stack with attacker-controlled data.

==2265506==ERROR: AddressSanitizer: stack-buffer-overflow on address 0x7ffec4971310 at pc 0x55e671b8a072 bp 0x7ffec4970f70 sp 0x7ffec4970f68
WRITE of size 1 at 0x7ffec4971310 thread T0

Ready to move

Start Securing

Free, no credit card | First findings in minutes