ImageMagick has a heap-buffer-overflow in NewXMLTree which could result in crash
Moderate severity
GitHub Reviewed
Published
Mar 16, 2026
in
ImageMagick/ImageMagick
•
Updated Mar 18, 2026
Description
Published to the GitHub Advisory Database
Mar 17, 2026
Reviewed
Mar 17, 2026
Published by the National Vulnerability Database
Mar 18, 2026
Last updated
Mar 18, 2026
The NewXMLTree method contains a bug that could result in a crash due to an out of write bounds of a single zero byte.
References