CVE-2026-103118: GraphicsMagick WPG File wpg.c ExtractPostscript recursion
A vulnerability was detected in GraphicsMagick up to 1.3.47. Affected by this vulnerability is the function ExtractPostscript of the file coders/wpg.c of the component WPG File Handler. Performing a manipulation results in uncontrolled recursion. The attack may be initiated remotely. The patch is named 627b5b1b2fc2. It is suggested to install a patch to address this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GraphicsMagickto a version that resolves this vulnerability.Patch 627b5b1b2fc2
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
An attacker can initiate the attack remotely by supplying manipulated WPG content for processing. No privileges are required, but user interaction is required according to the supplied vector.
Which deployments should be prioritized for remediation?
Prioritize systems that process WPG files with GraphicsMagick, especially where untrusted or externally supplied files can be opened or converted. The affected WPG File Handler is present in GraphicsMagick versions up to 1.3.47.
What is the likely operational impact?
The issue causes uncontrolled recursion in ExtractPostscript, which can result in an availability impact. The supplied assessment indicates no confidentiality or integrity impact.
What fix is available?
Apply the vendor-provided patch identified as 627b5b1b2fc2 or install the vendor's fixed release. The available data does not identify the first fixed version number.