Out-of-bounds read in ImageMagick - CVE-2026-47166
Published: May 19, 2026
ImageMagick
Detailed vulnerability description
The vulnerability allows a local privileged user to disclose sensitive information and cause a denial of service.
The vulnerability exists due to out-of-bounds read in the distributed pixel cache server when handling connections to the magick -distribute-cache service. A local privileged user can connect to the service to disclose sensitive information and cause a denial of service.