CVE-2026-40183

MEDIUM5.5EPSS 0.01%

ImageMagick has a heap buffer overflow when encoding JXL image with a 16-bit float

Published: 4/14/2026Modified: 5/17/2026

Description

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, the JXL encoder has an heap write overflow when a user specifies that the image should be encoded as 16 bit floats. This issue has been fixed in version 7.1.2-19.

Affected packages (18)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.5CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

References (7)