ImageMagick has a heap-use-after-free via XMP profile could result in a crash when printing the values. — CVE-2026-40311
GitHub · GitHub · CVE-2026-40311
ID
CVE-2026-40311
CVE-2026-40311
Date
Updated
Activity
Source
GitHub
GitHub
Vendor
GitHub
GitHub
Threat
medium
medium
CVSS
5.5
5.5
EPSS
0.00006
0.00006
Summary
An heap use after free when reading an invalid XMP profile could result in a crash due to an heap use after free when printing the values.
Product
nuget: Magick.NET-Q16-AnyCPU | nuget: Magick.NET-Q16-HDRI-AnyCPU | nuget: Magick.NET-Q16-HDRI-OpenMP-arm64 | nuget: Magick.NET-Q16-HDRI-arm64 | nuget: Magick.NET-Q16-HDRI-x64 | nuget: Magick.NET-Q16-HDRI-x86 | nuget: Magick.NET-Q16-OpenMP-arm64 | nuget: Magick.NET-Q16-OpenMP-x64 | +8
What to do
General, cautious steps (verify details in the official source):
- Review exposure and plan remediation based on risk and environment.
- Identify affected product versions in your inventory and verify whether you are impacted.
- Apply vendor patches/updates or recommended mitigations as soon as available.
- Read the official advisory for exact affected versions and remediation steps.