CVE-2026-33901 | ImageMagick up to 6.9.13-43/7.1.2-18 MVG Decoder heap-based overflow (GHSA-x9h5-r9v2-vcww)
A vulnerability classified as critical has been found in ImageMagick up to 6.9.13-43/7.1.2-18. The impacted element is an unknown function of the component MVG Decoder. This manipulation causes heap-based buffer overflow.
This vulnerability is registered as CVE-2026-33901. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.