Out-of-bounds read in ImageMagick - CVE-2026-45358
Published: May 16, 2026
ImageMagick
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in the meta encoder when parsing input. A remote attacker can send specially crafted input to disclose sensitive information.
The issue is caused by an off-by-one error and results in a single-byte heap buffer over-read.