Out-of-bounds read in ImageMagick - CVE-2026-42326
Published: May 16, 2026
ImageMagick
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information and cause a denial of service.
The vulnerability exists due to out-of-bounds read in the IPTC encoder when writing an IPTC output file. A remote attacker can supply a malicious input file to disclose sensitive information and cause a denial of service.
The out-of-bounds read is limited to a single byte.