MEDIUM 5.3 NuGet

ImageMagick has a heap-Buffer-Overflow write of a single zero byte when parsing xml.

GHSA-cr67-pvmx-2pp2 · CVE-2026-33899

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

When Magick parses an XML file it is possible that a single zero byte is written out of the bounds.

Ready to move

Start Securing

Free, no credit card | First findings in minutes