CVE-2026-33902: ImageMagick: Stack Overflow via Recursive FX Expression Parsing
Published Apr 13, 2026
·Updated
A stack overflow vulnerability in ImageMagick's FX expression parser allows an attacker to crash the process by providing a deeply nested expression.
Affected Software
18 affected componentsFixes available
ImageMagick ImageMagick<7.1.2-19, <6.9.13-44
nuget/Magick.NET-Q8-x86<14.12.0
14.12.0
nuget/Magick.NET-Q8-arm64<14.12.0
14.12.0
nuget/Magick.NET-Q8-OpenMP-x64<14.12.0
14.12.0
nuget/Magick.NET-Q8-OpenMP-arm64<14.12.0
14.12.0
nuget/Magick.NET-Q8-AnyCPU<14.12.0
14.12.0
nuget/Magick.NET-Q16-x86<14.12.0
14.12.0
nuget/Magick.NET-Q16-arm64<14.12.0
14.12.0
nuget/Magick.NET-Q16-OpenMP-x64<14.12.0
14.12.0
nuget/Magick.NET-Q16-OpenMP-arm64<14.12.0
14.12.0
nuget/Magick.NET-Q16-HDRI-x86<14.12.0
14.12.0
nuget/Magick.NET-Q16-HDRI-x64<14.12.0
14.12.0
nuget/Magick.NET-Q16-HDRI-arm64<14.12.0
14.12.0
nuget/Magick.NET-Q16-HDRI-OpenMP-arm64<14.12.0
14.12.0
nuget/Magick.NET-Q16-HDRI-AnyCPU<14.12.0
14.12.0
nuget/Magick.NET-Q16-AnyCPU<14.12.0
14.12.0
ImageMagick ImageMagick<6.9.13-44
ImageMagick ImageMagick>=7.0.0-0<7.1.2-19
Remediation
Event History
Apr 13, 2026
CVE Published
via MITRE·08:59 PM
Data Sourced
via MITRE·08:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
RemedyAffected Software
Apr 14, 2026
Advisory Published
via GitHub·06:48 PM
Data Sourced
via GitHub·06:48 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-33902?
CVE-2026-33902 is a critical severity vulnerability due to the potential for remote code execution through stack overflow.
2
How do I fix CVE-2026-33902?
To fix CVE-2026-33902, update ImageMagick to version 7.1.2-19 or 6.9.13-44 or later.
3
What versions of ImageMagick are affected by CVE-2026-33902?
CVE-2026-33902 affects versions of ImageMagick prior to 7.1.2-19 and 6.9.13-44.
4
Can CVE-2026-33902 be exploited remotely?
Yes, CVE-2026-33902 can be exploited remotely, allowing attackers to potentially execute arbitrary code.
5
What components of ImageMagick are vulnerable in CVE-2026-33902?
The vulnerability exists in the FX expression parser of ImageMagick, specifically in the recursive parsing functionality.