Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.9 NuGet

ImageMagick has a heap overflow caused by integer overflow/wraparound in viff encoder on 32-bit builds

GHSA-v67w-737x-v2c9 · CVE-2026-33900

Published · Modified

Description

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, the viff encoder contains an integer truncation/wraparound issue on 32-bit builds that could trigger an out of bounds heap write, potentially causing a crash. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.

Ready to move

Start Securing

Free, no credit card | First findings in minutes