Loading...
Skip to main content

CVE-2026-46522

HIGH

ImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustion

Published May 18, 2026Updated June 24, 2026Source: osv

Summary

Due to a missing check in the MIFF decoder a crafted file could cause an infinite loop resulting in CPU exhaustion.

Remediation

Upgrade to the fixed version using your package manager.

NuGet
Update Magick.NET-Q8-arm64 to 14.13.1 or later
dotnet add package Magick.NET-Q8-arm64 --version 14.13.1
NuGet
Update Magick.NET-Q16-x64 to 14.13.1 or later
dotnet add package Magick.NET-Q16-x64 --version 14.13.1
NuGet
Update Magick.NET-Q16-HDRI-arm64 to 14.13.1 or later
dotnet add package Magick.NET-Q16-HDRI-arm64 --version 14.13.1
NuGet
Update Magick.NET-Q8-x64 to 14.13.1 or later
dotnet add package Magick.NET-Q8-x64 --version 14.13.1
NuGet
Update Magick.NET-Q16-HDRI-x64 to 14.13.1 or later
dotnet add package Magick.NET-Q16-HDRI-x64 --version 14.13.1
NuGet
Update Magick.NET-Q16-x86 to 14.13.1 or later
dotnet add package Magick.NET-Q16-x86 --version 14.13.1
NuGet
Update Magick.NET-Q8-x86 to 14.13.1 or later
dotnet add package Magick.NET-Q8-x86 --version 14.13.1
NuGet
Update Magick.NET-Q16-HDRI-OpenMP-x64 to 14.13.1 or later
dotnet add package Magick.NET-Q16-HDRI-OpenMP-x64 --version 14.13.1
NuGet
Update Magick.NET-Q8-OpenMP-x64 to 14.13.1 or later
dotnet add package Magick.NET-Q8-OpenMP-x64 --version 14.13.1
NuGet
Update Magick.NET-Q16-AnyCPU to 14.13.1 or later
dotnet add package Magick.NET-Q16-AnyCPU --version 14.13.1
NuGet
Update Magick.NET-Q8-AnyCPU to 14.13.1 or later
dotnet add package Magick.NET-Q8-AnyCPU --version 14.13.1
NuGet
Update Magick.NET-Q8-OpenMP-arm64 to 14.13.1 or later
dotnet add package Magick.NET-Q8-OpenMP-arm64 --version 14.13.1
NuGet
Update Magick.NET-Q16-arm64 to 14.13.1 or later
dotnet add package Magick.NET-Q16-arm64 --version 14.13.1
NuGet
Update Magick.NET-Q16-HDRI-x86 to 14.13.1 or later
dotnet add package Magick.NET-Q16-HDRI-x86 --version 14.13.1
NuGet
Update Magick.NET-Q16-HDRI-AnyCPU to 14.13.1 or later
dotnet add package Magick.NET-Q16-HDRI-AnyCPU --version 14.13.1
NuGet
Update Magick.NET-Q16-OpenMP-arm64 to 14.13.1 or later
dotnet add package Magick.NET-Q16-OpenMP-arm64 --version 14.13.1
NuGet
Update Magick.NET-Q16-OpenMP-x64 to 14.13.1 or later
dotnet add package Magick.NET-Q16-OpenMP-x64 --version 14.13.1
NuGet
Update Magick.NET-Q16-HDRI-OpenMP-arm64 to 14.13.1 or later
dotnet add package Magick.NET-Q16-HDRI-OpenMP-arm64 --version 14.13.1

After upgrading, run your dependency scanner again to confirm the vulnerability is resolved.

Affected Packages (18)

PackageEcosystemAffectedFixed In
Magick.NET-Q8-arm64
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+56 more)14.13.1
Magick.NET-Q16-x64
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+227 more)14.13.1
Magick.NET-Q16-HDRI-arm64
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+56 more)14.13.1
Magick.NET-Q8-x64
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+227 more)14.13.1
Magick.NET-Q16-HDRI-x64
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+208 more)14.13.1
Magick.NET-Q16-x86
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+227 more)14.13.1
Magick.NET-Q8-x86
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+227 more)14.13.1
Magick.NET-Q16-HDRI-OpenMP-x64
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+108 more)14.13.1
Magick.NET-Q8-OpenMP-x64
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+108 more)14.13.1
Magick.NET-Q16-AnyCPU
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+211 more)14.13.1
Magick.NET-Q8-AnyCPU
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+211 more)14.13.1
Magick.NET-Q8-OpenMP-arm64
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+56 more)14.13.1
Magick.NET-Q16-arm64
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+56 more)14.13.1
Magick.NET-Q16-HDRI-x86
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+208 more)14.13.1
Magick.NET-Q16-HDRI-AnyCPU
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+208 more)14.13.1
Magick.NET-Q16-OpenMP-arm64
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+56 more)14.13.1
Magick.NET-Q16-OpenMP-x64
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+108 more)14.13.1
Magick.NET-Q16-HDRI-OpenMP-arm64
nuget
10.0.0, 10.1.0, 11.0.0, 11.1.0 (+56 more)14.13.1

Vulnerability Classification

Common Weakness Enumeration (CWE) identifiers for this vulnerability type.

CVSS Score Breakdown

What the CVSS (Common Vulnerability Scoring System) 7.5 score means for each attack dimension.

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Frequently Asked Questions

What is CVE-2026-46522?
ImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustion This vulnerability has been assigned a severity rating of HIGH (CVSS score: 7.5/10).
How do I check if my project is affected by CVE-2026-46522?
CVE-2026-46522 affects Magick.NET-Q8-arm64, Magick.NET-Q16-x64 and Magick.NET-Q16-HDRI-arm64 (and 15 more). Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2026-46522 and 200,000+ other known vulnerabilities.

Severity & Exploitability

CVSS Score
7.5

High exploitability or significant impact. Prioritize remediation within days.

Also Known As

GHSA-7gg8-qqx7-92g5

Related CVEs

  • CVE-2026-33908
    HIGH

    ImageMagick has a Stack Overflow in DestroyXMLTree()

  • CVE-2026-53461
    HIGH

    ImageMagick has out-of-bounds write in ICON decoder due to incorrect loop

  • CVE-2026-25985
    HIGH

    ImageMagick: Memory allocation with excessive without limits in the internal SVG decoder

  • CVE-2026-28690
    MEDIUM

    ImageMagick has stack write buffer overflow in MNG encoder

  • CVE-2026-46692
    MEDIUM

    ImageMagick: Heap Buffer Over-Write in distributed pixel cache server

  • CVE-2026-25984
    LOW

    ImageMagick: Integer Overflow in PSB (PSD v2) RLE decoding path causes heap Out of Bounds reads for 32-bit builds

  • CVE-2026-61864
    LOW

    ImageMagick: Memory Leak in color transformation to log colorspace when operation fails

  • CVE-2026-61858
    LOW

    ImageMagick: Policy Bypass in APNG encoder and delegates due to a missing check

Check if you're affected

Scan your dependencies to see if this vulnerability affects your projects.

Scan Your Dependencies