CVE-2026-23952: ImageMagick has a NULL pointer dereference in MSL parser via <comment> tag before image load
NULL pointer dereference in MSL (Magick Scripting Language) parser when processing <comment> tag before any image is loaded.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-23952 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →