A AegiFlow
LOWCVSS 3.3EPSS 0.1%

CVE-2026-56370

ImageMagick has out-of-bounds access in ConnectedComponentsImage() via CLI-controlled connected-components:* artifacts

Published
2026-04-14
Modified
2026-09-18
EPSS percentile
2%
Aliases
GHSA-pmpg-6pww-fg6q
Sources
github-advisory

Summary

When the `connected-components:*` define specifies an invalid index and out of bound operation will result in an access violation.

Affected packages

EcosystemPackageAffected versionsFixed versions
NuGetMagick.NET-Q16-AnyCPU14.12.0
NuGetMagick.NET-Q16-arm6414.12.0
NuGetMagick.NET-Q16-HDRI-AnyCPU14.12.0
NuGetMagick.NET-Q16-HDRI-arm6414.12.0
NuGetMagick.NET-Q16-HDRI-OpenMP-arm6414.12.0
NuGetMagick.NET-Q16-HDRI-OpenMP-x6414.12.0
NuGetMagick.NET-Q16-HDRI-x6414.12.0
NuGetMagick.NET-Q16-HDRI-x8614.12.0
NuGetMagick.NET-Q16-OpenMP-arm6414.12.0
NuGetMagick.NET-Q16-OpenMP-x6414.12.0
NuGetMagick.NET-Q16-x6414.12.0
NuGetMagick.NET-Q16-x8614.12.0
NuGetMagick.NET-Q8-AnyCPU14.12.0
NuGetMagick.NET-Q8-arm6414.12.0
NuGetMagick.NET-Q8-OpenMP-arm6414.12.0
NuGetMagick.NET-Q8-OpenMP-x6414.12.0
NuGetMagick.NET-Q8-x6414.12.0
NuGetMagick.NET-Q8-x8614.12.0

Remediation: Upgrade to 14.12.0 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.