CVE-2026-25898 | ImageMagick up to 6.9.13-39/7.1.2-14 UIL/XPM GetPixelIndex out-of-bounds (GHSA-vpxv-r9pg-7gpr)
A vulnerability was found in ImageMagick up to 6.9.13-39/7.1.2-14. It has been rated as critical. Affected is the function GetPixelIndex of the component UIL/XPM. Performing a manipulation results in out-of-bounds read.
This vulnerability is known as CVE-2026-25898. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.