CVE-2025-27795: High severity GraphicsMagick Graphicsmagick vulnerability
Last updated 14 April 2025
Other sources
ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/graphicsmagickto a version that resolves this vulnerability.Fixed in 1.4+really1.3.36+hg16481-2+deb11u1Fixed in 1.4+really1.3.40-4+deb12u1Fixed in 1.4+really1.3.45+hg17696-1 - Upgrade
Upgrade
GraphicsMagick (JXL)to a version that resolves this vulnerability.Fixed in 1.3.46
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27795?
CVE-2025-27795 is considered a high-severity vulnerability due to the potential for resource exhaustion attacks.
How do I fix CVE-2025-27795?
To fix CVE-2025-27795, upgrade GraphicsMagick to version 1.3.46 or later.
What systems are affected by CVE-2025-27795?
CVE-2025-27795 affects versions of GraphicsMagick prior to 1.3.46.
What type of attack does CVE-2025-27795 enable?
CVE-2025-27795 enables denial-of-service attacks due to the lack of resource limits on image dimensions.
Is there a workaround for CVE-2025-27795?
Currently, there are no known workarounds for CVE-2025-27795; updating to the latest version is the only solution.