GHSA-p93h-f2jc-477j — Magick.NET-Q16-AnyCPU
MEDIUMGHSA-p93h-f2jc-477j is a medium-severity (CVSS 4.1) CWE-122 vulnerability in Magick.NET-Q16-AnyCPU. A fix is available for Magick.NET-Q16-AnyCPU — see the affected versions and patch details below.
ImageMagick: Heap Buffer Over-Write in distributed pixel cache server
Exploitation Status
No confirmed exploitation observed yet
- CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.
Exploitation and automatability from CISA’s SSVC triage for GHSA-p93h-f2jc-477j.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
How urgent is this, really
GHSA-p93h-f2jc-477j by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.
Where this sits among everything scored
Of 382,574 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.
Real-World Exposure
Magick.NET-Q16-AnyCPU.NETMagick.NET-Q16-HDRI-AnyCPU.NETMagick.NET-Q16-HDRI-OpenMP-arm64.NETMagick.NET-Q16-HDRI-arm64.NETMagick.NET-Q16-HDRI-x64.NETMagick.NET-Q16-HDRI-x86.NETMagick.NET-Q16-OpenMP-arm64.NETMagick.NET-Q16-OpenMP-x64+9 moreReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects NuGet packages — download data is not available via public APIs for these ecosystems.
Description
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker who can connect to a magick -distribute-cache service can cause a heap buffer over-write in the server process. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| .NETNuGet | Magick.NET-Q16-AnyCPU | all versions | 14.12.0dotnet add package Magick.NET-Q16-AnyCPU --version 14.12.0 |
| .NETNuGet | Magick.NET-Q16-HDRI-AnyCPU | all versions | 14.12.0dotnet add package Magick.NET-Q16-HDRI-AnyCPU --version 14.12.0 |
| .NETNuGet | Magick.NET-Q16-HDRI-OpenMP-arm64 | all versions | 14.12.0dotnet add package Magick.NET-Q16-HDRI-OpenMP-arm64 --version 14.12.0 |
| .NETNuGet | Magick.NET-Q16-HDRI-arm64 | all versions | 14.12.0dotnet add package Magick.NET-Q16-HDRI-arm64 --version 14.12.0 |
| .NETNuGet | Magick.NET-Q16-HDRI-x64 | all versions | 14.12.0dotnet add package Magick.NET-Q16-HDRI-x64 --version 14.12.0 |
| .NETNuGet | Magick.NET-Q16-HDRI-x86 | all versions | 14.12.0dotnet add package Magick.NET-Q16-HDRI-x86 --version 14.12.0 |
Affected Products
imagemagickimagemagickDetection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for Magick.NET-Q16-AnyCPU, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update Magick.NET-Q16-AnyCPU to 14.12.0 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-p93h-f2jc-477j is resolved across your whole dependency graph.
Workarounds
Constrain what reaches the vulnerable code: limit the size and shape of untrusted input, isolate the affected component in a sandboxed or least-privileged process, and enable the platform's memory-safety mitigations (ASLR, stack protector, hardened allocator) so an out-of-bounds access is more likely to fail closed than to be exploitable.
Fixing This On Your OS
If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.
Moderate: A heap buffer overwrite vulnerability in ImageMagick's `magick -distribute-cache` service allows a remote, unauthenticated attacker to cause a denial of service. This flaw requires the `magick -distribute-cache` service to be explicitly enabled and exposed, as it is not enabled by default in Red Hat…
| Product | Fixed in | Advisory |
|---|---|---|
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | ImageMagick-0:6.9.10.68-17.el7_9 | RHSA-2026:32961 |
Frequently Asked Questions
Is GHSA-p93h-f2jc-477j in your dependencies?
Find it across NuGet, including transitive dependencies.