CVE-2026-40183: ImageMagick: Heap buffer overflow when encoding JXL image with a 16-bit float
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, the JXL encoder has an heap write overflow when a user specifies that the image should be encoded as 16 bit floats. This issue has been fixed in version 7.1.2-19.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40183?
CVE-2026-40183 is rated as a high-severity vulnerability due to the potential for exploitation through heap buffer overflow.
How do I fix CVE-2026-40183?
To mitigate CVE-2026-40183, upgrade ImageMagick to version 7.1.2-19 or later.
What versions are affected by CVE-2026-40183?
CVE-2026-40183 affects all versions of ImageMagick prior to 7.1.2-19.
What types of attacks could exploit CVE-2026-40183?
CVE-2026-40183 could potentially be exploited to execute arbitrary code or cause a denial of service.
Is CVE-2026-40183 specific to a certain image format?
Yes, CVE-2026-40183 specifically affects the JXL image encoding functionality within ImageMagick.