Record summary

CVE-2026-32636 has a selected CVSS score of 5.3 (medium).

Description

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-17 and 6.9.13-42, the NewXMLTree method contains a bug that could result in a crash due to an out of write bounds of a single zero byte. Versions 7.1.2-17 and 6.9.13-42 fix the issue.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 19, 2026 · Source: CVE List

Affected products and versions

Showing 12 of 20
ProductSourceVersion rangeStatus
CVE List< 6.9.13-42affected
< 7.1.2-17affected
GitHub AdvisoryBefore 14.11.0 · Fixed in 14.11.0affected
GitHub AdvisoryBefore 14.11.0 · Fixed in 14.11.0affected

Magick.NET-Q16-HDRI-OpenMP-arm64

Browse NuGet / Magick.NET-Q16-HDRI-OpenMP-arm64
GitHub AdvisoryBefore 14.11.0 · Fixed in 14.11.0affected

Magick.NET-Q16-HDRI-OpenMP-x64

Browse NuGet / Magick.NET-Q16-HDRI-OpenMP-x64
GitHub AdvisoryBefore 14.11.0 · Fixed in 14.11.0affected
GitHub AdvisoryBefore 14.11.0 · Fixed in 14.11.0affected
GitHub AdvisoryBefore 14.11.0 · Fixed in 14.11.0affected
GitHub AdvisoryBefore 14.11.0 · Fixed in 14.11.0affected
GitHub AdvisoryBefore 14.11.0 · Fixed in 14.11.0affected
GitHub AdvisoryBefore 14.11.0 · Fixed in 14.11.0affected
GitHub AdvisoryBefore 14.11.0 · Fixed in 14.11.0affected
GitHub AdvisoryBefore 14.11.0 · Fixed in 14.11.0affected

References

5