Advisory Database
  • Advisories
  • Dependency Scanning
  1. nuget
  2. ›
  3. Magick.NET-Q8-OpenMP-arm64
  4. ›
  5. CVE-2026-28493

CVE-2026-28493: ImageMagick has Integer Overflow leading to out of bounds write in SIXEL decoder

March 12, 2026

An integer overflow vulnerability exists in the SIXEL decoer. The vulnerability allows an attacker to perform an out of bounds via a specially crafted mage.

References

  • github.com/ImageMagick/ImageMagick
  • github.com/ImageMagick/ImageMagick/security/advisories/GHSA-r39q-jr8h-gcq2
  • github.com/advisories/GHSA-r39q-jr8h-gcq2
  • github.com/dlemstra/Magick.NET/releases/tag/14.10.4
  • nvd.nist.gov/vuln/detail/CVE-2026-28493

Code Behaviors & Features

Detect and mitigate CVE-2026-28493 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 14.10.4

Fixed versions

  • 14.10.4

Solution

Upgrade to version 14.10.4 or above.

Impact 6.5 MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H

Learn more about CVSS

Weakness

  • CWE-190: Integer Overflow or Wraparound

Source file

nuget/Magick.NET-Q8-OpenMP-arm64/CVE-2026-28493.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 24 Mar 2026 12:17:26 +0000.