CVE-2026-40312: ImageMagick: Off-by-One in MSL decoder could result in crash
Published Apr 13, 2026
·Updated
An off by one error in de MSL decoder could result in a crash when a malicous msl file is read.
Affected Software
17 affected componentsFixes available
ImageMagick ImageMagick<7.1.2-19
nuget/Magick.NET-Q8-x86<14.12.0
14.12.0
nuget/Magick.NET-Q8-arm64<14.12.0
14.12.0
nuget/Magick.NET-Q8-OpenMP-x64<14.12.0
14.12.0
nuget/Magick.NET-Q8-OpenMP-arm64<14.12.0
14.12.0
nuget/Magick.NET-Q8-AnyCPU<14.12.0
14.12.0
nuget/Magick.NET-Q16-x86<14.12.0
14.12.0
nuget/Magick.NET-Q16-arm64<14.12.0
14.12.0
nuget/Magick.NET-Q16-OpenMP-x64<14.12.0
14.12.0
nuget/Magick.NET-Q16-OpenMP-arm64<14.12.0
14.12.0
nuget/Magick.NET-Q16-HDRI-x86<14.12.0
14.12.0
nuget/Magick.NET-Q16-HDRI-x64<14.12.0
14.12.0
nuget/Magick.NET-Q16-HDRI-arm64<14.12.0
14.12.0
nuget/Magick.NET-Q16-HDRI-OpenMP-arm64<14.12.0
14.12.0
nuget/Magick.NET-Q16-HDRI-AnyCPU<14.12.0
14.12.0
nuget/Magick.NET-Q16-AnyCPU<14.12.0
14.12.0
ImageMagick ImageMagick<7.1.2-19
Remediation
Event History
Apr 13, 2026
CVE Published
via MITRE·09:43 PM
Data Sourced
via MITRE·09:43 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
RemedyAffected Software
Apr 14, 2026
Advisory Published
via GitHub·07:10 PM
Data Sourced
via GitHub·07:10 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-40312?
CVE-2026-40312 is considered a moderate severity vulnerability due to its potential to cause application crashes.
2
How do I fix CVE-2026-40312?
To fix CVE-2026-40312, upgrade ImageMagick to version 7.1.2-19 or later.
3
What type of vulnerability is CVE-2026-40312?
CVE-2026-40312 is an off-by-one error vulnerability in the MSL decoder.
4
Which versions of ImageMagick are affected by CVE-2026-40312?
ImageMagick versions prior to 7.1.2-19 are affected by CVE-2026-40312.
5
What may happen when CVE-2026-40312 is exploited?
Exploitation of CVE-2026-40312 could result in a crash of the ImageMagick application.