CVE-2026-33902 is a stack overflow vulnerability in ImageMagick's FX expression parser that affects versions below 6.9.13-44 and 7.1.2-19. An attacker can trigger a denial of service by submitting deeply nested expressions to crash the affected process. The vulnerability has been patched in the aforementioned versions. The vulnerability carries a CVSS score of 5.5 (Medium severity) and requires local access with user interaction but no privileges. The attack vector is local, and the only impact is availability, as the vulnerability enables process crashes rather than data compromise or system takeover. The FAUCET Risk Score of 41.0 indicates moderate concern within the broader vulnerability landscape. There is no evidence of active exploitation in the wild. The CVE is not listed on the Known Exploited Vulnerabilities (KEV) catalog, and it remains inactive on threat intelligence hotlists. The low EPSS score of 0.00013 further suggests minimal real-world exploitation activity, indicating this is a lower-priority issue for organizations despite requiring timely patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.9.13-44CPE matchmatch criteria | cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:* | ||
>= 7.0.0-0, < 7.1.2-19CPE matchmatch criteria | cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.