Description
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, a heap buffer over-write can occur in the fx operation by passing a crafted argument. This issue has been fixed in version 7.1.2-27.
Published: 2026-07-30
Score: 5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

ImageMagick versions before 7.1.2-27 allow an attacker to trigger a heap buffer over-write by passing a specially crafted argument to the fx operation. This flaw can corrupt memory on the host and may lead to application instability or denial of service. The weakness is identified as CWE-787.

Affected Systems

The affected product is ImageMagick. All releases older than version 7.1.2‑27 are vulnerable.

Risk and Exploitability

The CVSS score of 5 indicates moderate severity, and the EPSS score of less than 1% suggests that the probability of exploitation is currently low. The vulnerability is not listed as a known exploit in the CISA KEV catalog. Based on the description, the likely attack vector is the execution of maliciously crafted image data through the fx operation, which could be triggered when processing untrusted images or input files. The CVE data does not specify the privilege level required to supply the crafted argument.

Generated by OpenCVE AI on August 4, 2026 at 12:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ImageMagick to version 7.1.2‑27 or later.
  • If an upgrade is not immediately possible, limit the use of the fx operation to trusted images and validate input before processing.
  • Implement monitoring for unexpected application crashes or memory errors that may indicate exploitation.

Generated by OpenCVE AI on August 4, 2026 at 12:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-422r-8c97-xcg4 ImageMagick: Heap Buffer Over-Write in fx operation
History

Thu, 30 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 30 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Imagemagick
Imagemagick imagemagick
Vendors & Products Imagemagick
Imagemagick imagemagick

Thu, 30 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Description ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, a heap buffer over-write can occur in the fx operation by passing a crafted argument. This issue has been fixed in version 7.1.2-27.
Title ImageMagick: Heap Buffer Over-Write in fx operation
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

Imagemagick Imagemagick
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-30T13:08:51.019Z

Reserved: 2026-07-13T22:04:59.677Z

Link: CVE-2026-62363

cve-icon Vulnrichment

Updated: 2026-07-30T13:08:47.723Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T00:16:25.213

Modified: 2026-08-03T16:25:12.310

Link: CVE-2026-62363

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-30T00:02:33Z

Links: CVE-2026-62363 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T12:30:09Z

Weaknesses