CVE-2026-28686 describes a heap-buffer-overflow vulnerability in ImageMagick, affecting versions prior to 7.1.2-16 and 6.9.13-41, due to an undersized output buffer allocation within the PCL encode function. Rated Medium with a CVSS score of 6.8, this vulnerability has a local attack vector and could lead to a high impact on availability and a low impact on integrity. Currently, there is no evidence of active exploitation, public exploit code availability, or significant community discussion regarding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.9.13-41CPE matchmatch criteria | cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:* | ||
>= 7.0.0-0, < 7.1.2-16CPE matchmatch criteria | cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.