CVE-2026-56369 — Magick.NET-Q16-AnyCPU
CVE-2026-56369 is a CWE-323 vulnerability in Magick.NET-Q16-AnyCPU. A fix is available for Magick.NET-Q16-AnyCPU — see the affected versions and patch details below.
ImageMagick - Information Disclosure via AES-CTR Nonce Reuse in PasskeyEncipherImage
Exploitation Status
No confirmed exploitation observed yet
- CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.
Exploitation and automatability from CISA’s SSVC triage for CVE-2026-56369.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
Real-World Exposure
Magick.NET-Q16-AnyCPU.NETMagick.NET-Q16-HDRI-AnyCPU.NETMagick.NET-Q16-HDRI-OpenMP-arm64.NETMagick.NET-Q16-HDRI-arm64.NETMagick.NET-Q16-HDRI-x64.NETMagick.NET-Q16-HDRI-x86.NETMagick.NET-Q16-OpenMP-arm64.NETMagick.NET-Q16-OpenMP-x64+9 moreReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects NuGet packages — download data is not available via public APIs for these ecosystems.
Description
ImageMagick before 7.1.2-22 contains an information disclosure vulnerability in the PasskeyEncipherImage method due to AES-CTR nonce reuse. Attackers can exploit nonce reuse in the cipher implementation to recover plaintext information from encrypted images.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| .NETNuGet | Magick.NET-Q16-AnyCPU | all versions | 14.12.0dotnet add package Magick.NET-Q16-AnyCPU --version 14.12.0 |
| .NETNuGet | Magick.NET-Q16-HDRI-AnyCPU | all versions | 14.12.0dotnet add package Magick.NET-Q16-HDRI-AnyCPU --version 14.12.0 |
| .NETNuGet | Magick.NET-Q16-HDRI-OpenMP-arm64 | all versions | 14.12.0dotnet add package Magick.NET-Q16-HDRI-OpenMP-arm64 --version 14.12.0 |
| .NETNuGet | Magick.NET-Q16-HDRI-arm64 | all versions | 14.12.0dotnet add package Magick.NET-Q16-HDRI-arm64 --version 14.12.0 |
| .NETNuGet | Magick.NET-Q16-HDRI-x64 | all versions | 14.12.0dotnet add package Magick.NET-Q16-HDRI-x64 --version 14.12.0 |
| .NETNuGet | Magick.NET-Q16-HDRI-x86 | all versions | 14.12.0dotnet add package Magick.NET-Q16-HDRI-x86 --version 14.12.0 |
Affected Products
imagemagickimagemagickDetection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for Magick.NET-Q16-AnyCPU, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update Magick.NET-Q16-AnyCPU to 14.12.0 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-56369 is resolved across your whole dependency graph.
Workarounds
Assume what was exposed is already known: rotate any credential, token or key that the affected component could return, restrict the endpoint to callers that genuinely need it, and strip sensitive fields from responses and error output at the boundary rather than relying on the client not to read them.
Fixing This On Your OS
If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.
This Low impact information disclosure flaw in ImageMagick arises from AES-CTR nonce reuse within the `PasskeyEncipherImage` method. Exploitation requires an attacker to specifically target encrypted images processed by this method, which is not a common default configuration in Red Hat environments. The vulnerability…
To mitigate this stop using ImageMagick's built-in encryption feature. Rely on standard, OS-level data-at-rest encryption (such as LUKS) to protect sensitive media instead.Source: Red Hat security advisory for CVE-2026-56369 (CC BY 4.0)
Frequently Asked Questions
Is CVE-2026-56369 in your dependencies?
Find it across NuGet, including transitive dependencies.