CVE-2026-55577: ImageMagick: Heap Buffer Overflow in ImageMagick MVG decoder
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 6.9.13-51 - Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 7.1.2-26
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55577?
The severity of CVE-2026-55577 is classified as medium with a score of 5.9.
How do I fix CVE-2026-55577?
To fix CVE-2026-55577, update ImageMagick to versions 6.9.13-51 or 7.1.2-26 or later.
What type of vulnerability is CVE-2026-55577?
CVE-2026-55577 is a heap buffer overflow vulnerability in the ImageMagick MVG decoder.
What could be the impact of CVE-2026-55577?
CVE-2026-55577 could lead to an out of bounds write when processing a specially crafted image.
In which software is CVE-2026-55577 found?
CVE-2026-55577 is found in the ImageMagick software, used for editing and manipulating digital images.