#VU125879 Integer overflow in ImageMagick - CVE-2026-33900
Published: April 14, 2026
ImageMagick
ImageMagick.org
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow or wraparound in the viff encoder when processing crafted input on 32-bit builds. A remote attacker can send a specially crafted file to trigger an out-of-bounds heap write and cause a denial of service.
Only 32-bit builds are vulnerable.