#VU125881 Uncontrolled Recursion in ImageMagick - CVE-2026-33902
Published: April 14, 2026
ImageMagick
ImageMagick.org
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled recursion in the FX expression parser when parsing deeply nested expressions. A remote attacker can provide a deeply nested expression to cause a denial of service.
User interaction is required to process the crafted expression.