CVE-2026-46692: ImageMagick: Heap Buffer Over-Write in distributed pixel cache server
An attacker who can connect to a magick -distribute-cache service can cause a heap buffer over-write in the server process.
Other sources
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker who can connect to a magick -distribute-cache service can cause a heap buffer over-write in the server process. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nuget/Magick.NET-Q8-x86to a version that resolves this vulnerability.Fixed in 14.12.0 - Upgrade
Upgrade
nuget/Magick.NET-Q8-x64to a version that resolves this vulnerability.Fixed in 14.12.0 - Upgrade
Upgrade
nuget/Magick.NET-Q8-arm64to a version that resolves this vulnerability.Fixed in 14.12.0 - Upgrade
Upgrade
nuget/Magick.NET-Q8-OpenMP-x64to a version that resolves this vulnerability.Fixed in 14.12.0 - Upgrade
Upgrade
nuget/Magick.NET-Q8-OpenMP-arm64to a version that resolves this vulnerability.Fixed in 14.12.0 - Upgrade
Upgrade
nuget/Magick.NET-Q8-AnyCPUto a version that resolves this vulnerability.Fixed in 14.12.0 - Upgrade
Upgrade
nuget/Magick.NET-Q16-x86to a version that resolves this vulnerability.Fixed in 14.12.0 - Upgrade
Upgrade
nuget/Magick.NET-Q16-x64to a version that resolves this vulnerability.Fixed in 14.12.0 - Upgrade
Upgrade
nuget/Magick.NET-Q16-arm64to a version that resolves this vulnerability.Fixed in 14.12.0 - Upgrade
Upgrade
nuget/Magick.NET-Q16-OpenMP-x64to a version that resolves this vulnerability.Fixed in 14.12.0 - Upgrade
Upgrade
nuget/Magick.NET-Q16-OpenMP-arm64to a version that resolves this vulnerability.Fixed in 14.12.0 - Upgrade
Upgrade
nuget/Magick.NET-Q16-HDRI-x86to a version that resolves this vulnerability.Fixed in 14.12.0 - Upgrade
Upgrade
nuget/Magick.NET-Q16-HDRI-x64to a version that resolves this vulnerability.Fixed in 14.12.0 - Upgrade
Upgrade
nuget/Magick.NET-Q16-HDRI-arm64to a version that resolves this vulnerability.Fixed in 14.12.0 - Upgrade
Upgrade
nuget/Magick.NET-Q16-HDRI-OpenMP-arm64to a version that resolves this vulnerability.Fixed in 14.12.0 - Upgrade
Upgrade
nuget/Magick.NET-Q16-HDRI-AnyCPUto a version that resolves this vulnerability.Fixed in 14.12.0 - Upgrade
Upgrade
nuget/Magick.NET-Q16-AnyCPUto a version that resolves this vulnerability.Fixed in 14.12.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.9.13-48 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.1.2-23
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46692?
CVE-2026-46692 has a medium severity rating of 4.1.
How do I fix CVE-2026-46692?
To fix CVE-2026-46692, update to the latest version of Magick.NET that addresses this vulnerability.
What is the impact of CVE-2026-46692 on affected software?
CVE-2026-46692 allows an attacker to cause a heap buffer over-write in the server process when connected to a 'magick -distribute-cache' service.
Which software versions are affected by CVE-2026-46692?
CVE-2026-46692 affects multiple versions of Magick.NET including Q8 and Q16 for x86, ARM64, OpenMP, and AnyCPU.
What types of attacks are possible with CVE-2026-46692?
An attacker may execute remote code or crash the service by exploiting the heap buffer over-write vulnerability in CVE-2026-46692.