CVE-2026-33908 is a stack exhaustion vulnerability affecting ImageMagick image manipulation software in versions prior to 6.9.13-44 and 7.1.2-19. The flaw exists in the recursive XML tree destruction function, which lacks depth limiting controls, allowing attackers to trigger a denial of service condition by submitting XML files with deeply nested structures. The vulnerability carries a CVSS 7.5 HIGH severity rating due to its network-accessible attack vector, low complexity requirements, and lack of authentication needed for exploitation. However, the impact is limited to availability rather than confidentiality or integrity, as successful exploitation exhausts stack memory rather than compromising data or system control. This vulnerability is not currently listed on the Known Exploited Vulnerabilities catalog and demonstrates minimal real-world activity with an EPSS score of 0.00018, indicating very low probability of active exploitation. The moderate FAUCET risk score of 48.0 suggests limited community attention despite the high CVSS rating. Organizations should prioritize patching based on their deployment of vulnerable ImageMagick versions rather than immediate exploitation concerns.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.9.13-44CPE matchmatch criteria | cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:* | ||
>= 7.0.0-0, < 7.1.2-19CPE matchmatch criteria | cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.