Loading...
Skip to main content

CVE-2026-40183

MEDIUM

ImageMagick has a heap buffer overflow when encoding JXL image with a 16-bit float

Published April 14, 2026Updated May 9, 2026Source: osv

Summary

The JXL encoder has an heap write overflow when a user specifies that the image should be encoded as 16 bit floats.

Remediation

Upgrade to the fixed version using your package manager.

NuGet
Update Magick.NET-Q8-arm64 to 14.12.0 or later
dotnet add package Magick.NET-Q8-arm64 --version 14.12.0
NuGet
Update Magick.NET-Q16-OpenMP-x64 to 14.12.0 or later
dotnet add package Magick.NET-Q16-OpenMP-x64 --version 14.12.0
NuGet
Update Magick.NET-Q16-OpenMP-arm64 to 14.12.0 or later
dotnet add package Magick.NET-Q16-OpenMP-arm64 --version 14.12.0
NuGet
Update Magick.NET-Q8-OpenMP-x64 to 14.12.0 or later
dotnet add package Magick.NET-Q8-OpenMP-x64 --version 14.12.0
NuGet
Update Magick.NET-Q8-x64 to 14.12.0 or later
dotnet add package Magick.NET-Q8-x64 --version 14.12.0
NuGet
Update Magick.NET-Q8-OpenMP-arm64 to 14.12.0 or later
dotnet add package Magick.NET-Q8-OpenMP-arm64 --version 14.12.0
NuGet
Update Magick.NET-Q16-x64 to 14.12.0 or later
dotnet add package Magick.NET-Q16-x64 --version 14.12.0
NuGet
Update Magick.NET-Q16-HDRI-AnyCPU to 14.12.0 or later
dotnet add package Magick.NET-Q16-HDRI-AnyCPU --version 14.12.0
NuGet
Update Magick.NET-Q16-HDRI-OpenMP-arm64 to 14.12.0 or later
dotnet add package Magick.NET-Q16-HDRI-OpenMP-arm64 --version 14.12.0
NuGet
Update Magick.NET-Q16-arm64 to 14.12.0 or later
dotnet add package Magick.NET-Q16-arm64 --version 14.12.0
NuGet
Update Magick.NET-Q16-HDRI-x86 to 14.12.0 or later
dotnet add package Magick.NET-Q16-HDRI-x86 --version 14.12.0
NuGet
Update Magick.NET-Q16-x86 to 14.12.0 or later
dotnet add package Magick.NET-Q16-x86 --version 14.12.0
NuGet
Update Magick.NET-Q16-AnyCPU to 14.12.0 or later
dotnet add package Magick.NET-Q16-AnyCPU --version 14.12.0
NuGet
Update Magick.NET-Q8-AnyCPU to 14.12.0 or later
dotnet add package Magick.NET-Q8-AnyCPU --version 14.12.0
NuGet
Update Magick.NET-Q16-HDRI-arm64 to 14.12.0 or later
dotnet add package Magick.NET-Q16-HDRI-arm64 --version 14.12.0
NuGet
Update Magick.NET-Q8-x86 to 14.12.0 or later
dotnet add package Magick.NET-Q8-x86 --version 14.12.0
NuGet
Update Magick.NET-Q16-HDRI-x64 to 14.12.0 or later
dotnet add package Magick.NET-Q16-HDRI-x64 --version 14.12.0

After upgrading, run your dependency scanner again to confirm the vulnerability is resolved.

Affected Packages (17)

PackageEcosystemAffectedFixed In
Magick.NET-Q8-arm64
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+54 more)14.12.0
Magick.NET-Q16-OpenMP-x64
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+106 more)14.12.0
Magick.NET-Q16-OpenMP-arm64
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+54 more)14.12.0
Magick.NET-Q8-OpenMP-x64
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+106 more)14.12.0
Magick.NET-Q8-x64
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+225 more)14.12.0
Magick.NET-Q8-OpenMP-arm64
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+54 more)14.12.0
Magick.NET-Q16-x64
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+225 more)14.12.0
Magick.NET-Q16-HDRI-AnyCPU
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+206 more)14.12.0
Magick.NET-Q16-HDRI-OpenMP-arm64
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+54 more)14.12.0
Magick.NET-Q16-arm64
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+54 more)14.12.0
Magick.NET-Q16-HDRI-x86
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+206 more)14.12.0
Magick.NET-Q16-x86
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+225 more)14.12.0
Magick.NET-Q16-AnyCPU
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+209 more)14.12.0
Magick.NET-Q8-AnyCPU
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+209 more)14.12.0
Magick.NET-Q16-HDRI-arm64
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+54 more)14.12.0
Magick.NET-Q8-x86
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+225 more)14.12.0
Magick.NET-Q16-HDRI-x64
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+206 more)14.12.0

Vulnerability Classification

Common Weakness Enumeration (CWE) identifiers for this vulnerability type.

CVSS Score Breakdown

What the CVSS (Common Vulnerability Scoring System) 5.5 score means for each attack dimension.

Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Frequently Asked Questions

What is CVE-2026-40183?
ImageMagick has a heap buffer overflow when encoding JXL image with a 16-bit float This vulnerability has been assigned a severity rating of MEDIUM (CVSS score: 5.5/10).
How do I check if my project is affected by CVE-2026-40183?
CVE-2026-40183 affects Magick.NET-Q8-arm64, Magick.NET-Q16-OpenMP-x64 and Magick.NET-Q16-OpenMP-arm64 (and 14 more). Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2026-40183 and 200,000+ other known vulnerabilities.

Severity & Exploitability

CVSS Score
5.5

Exploitation requires specific conditions or has limited impact. Remediate within weeks.

Also Known As

GHSA-jvgr-9ph5-m8v4

Related CVEs

  • CVE-2026-33908
    HIGH

    ImageMagick has a Stack Overflow in DestroyXMLTree()

  • CVE-2026-25985
    HIGH

    ImageMagick: Memory allocation with excessive without limits in the internal SVG decoder

  • CVE-2026-25983
    MEDIUM

    ImageMagick has Use After Free in MSLStartElement in "coders/msl.c"

  • CVE-2026-25795
    MEDIUM

    ImageMagick has NULL pointer dereference in ReadSFWImage after DestroyImageInfo (sfw.c)

  • CVE-2026-25984
    LOW

    ImageMagick: Integer Overflow in PSB (PSD v2) RLE decoding path causes heap Out of Bounds reads for 32-bit builds

  • CVE-2026-56376
    LOW

    ImageMagick has a possible heap Use After Free vulnerability in its meta coder

  • CVE-2026-61864
    LOW

    ImageMagick: Memory Leak in color transformation to log colorspace when operation fails

  • CVE-2026-61858
    LOW

    ImageMagick: Policy Bypass in APNG encoder and delegates due to a missing check

Check if you're affected

Scan your dependencies to see if this vulnerability affects your projects.

Scan Your Dependencies