HIGH 7.5 NuGet

ImageMagick has a Stack Overflow in DestroyXMLTree()

GHSA-fwvm-ggf6-2p4x · CVE-2026-33908

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Magick frees the memory of the XML tree via the DestroyXMLTree function; however, this process is executed recursively with no depth limit imposed. When magick processes an XML file with deeply nested structures, it will exhaust the stack memory, resulting in a Denial of Service (DoS) attack.

Ready to move

Start Securing

Free, no credit card | First findings in minutes