CVE-2026-40169: ImageMagick: Heap buffer overflow (WRITE) in the YAML and JSON encoders
Published Apr 13, 2026
·Updated
A crafted image could result in an out of bounds heap write when writing a yaml or json output and that could result in a crash.
Affected Software
17 affected componentsFixes available
ImageMagick ImageMagick<7.1.2-19
nuget/Magick.NET-Q8-x86<14.12.0
14.12.0
nuget/Magick.NET-Q8-arm64<14.12.0
14.12.0
nuget/Magick.NET-Q8-OpenMP-x64<14.12.0
14.12.0
nuget/Magick.NET-Q8-OpenMP-arm64<14.12.0
14.12.0
nuget/Magick.NET-Q8-AnyCPU<14.12.0
14.12.0
nuget/Magick.NET-Q16-x86<14.12.0
14.12.0
nuget/Magick.NET-Q16-arm64<14.12.0
14.12.0
nuget/Magick.NET-Q16-OpenMP-x64<14.12.0
14.12.0
nuget/Magick.NET-Q16-OpenMP-arm64<14.12.0
14.12.0
nuget/Magick.NET-Q16-HDRI-x86<14.12.0
14.12.0
nuget/Magick.NET-Q16-HDRI-x64<14.12.0
14.12.0
nuget/Magick.NET-Q16-HDRI-arm64<14.12.0
14.12.0
nuget/Magick.NET-Q16-HDRI-OpenMP-arm64<14.12.0
14.12.0
nuget/Magick.NET-Q16-HDRI-AnyCPU<14.12.0
14.12.0
nuget/Magick.NET-Q16-AnyCPU<14.12.0
14.12.0
ImageMagick ImageMagick<7.1.2-19
Remediation
Event History
Apr 13, 2026
CVE Published
via MITRE·09:25 PM
Data Sourced
via MITRE·09:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 14, 2026
Advisory Published
via GitHub·06:50 PM
Data Sourced
via GitHub·06:50 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-40169?
CVE-2026-40169 has been classified as a medium severity vulnerability due to the potential for a heap buffer overflow leading to out of bounds writes.
2
How do I fix CVE-2026-40169?
To fix CVE-2026-40169, update ImageMagick to version 7.1.2-19 or later.
3
What types of files are affected by CVE-2026-40169?
CVE-2026-40169 specifically affects the YAML and JSON encoders in ImageMagick.
4
What could an attacker achieve by exploiting CVE-2026-40169?
An attacker could exploit CVE-2026-40169 to potentially execute arbitrary code or crash the application.
5
Which versions of ImageMagick are vulnerable to CVE-2026-40169?
Versions of ImageMagick prior to 7.1.2-19 are vulnerable to CVE-2026-40169.