When writing an IPTC output file a malicious input file could cause an out of bounds read of a single byte.
No EPSS score in this advisory JSON.
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 5.1 | 3.1 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-7wff-wpr6-vmhm ↗ |
| CVE | CVE-2026-42326 ↗ |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| nuget | Magick.NET-Q16-AnyCPU | < 14.13.1 | 14.13.1 | — |
| nuget | Magick.NET-Q16-HDRI-AnyCPU | < 14.13.1 | 14.13.1 | — |
| nuget | Magick.NET-Q16-HDRI-OpenMP-arm64 | < 14.13.1 | 14.13.1 | — |
| nuget | Magick.NET-Q16-HDRI-OpenMP-x64 | < 14.13.1 | 14.13.1 | — |
| nuget | Magick.NET-Q16-HDRI-arm64 | < 14.13.1 | 14.13.1 | — |
| nuget | Magick.NET-Q16-HDRI-x64 | < 14.13.1 | 14.13.1 | — |
| nuget | Magick.NET-Q16-HDRI-x86 | < 14.13.1 | 14.13.1 | — |
| nuget | Magick.NET-Q16-OpenMP-arm64 | < 14.13.1 | 14.13.1 | — |
| nuget | Magick.NET-Q16-OpenMP-x64 | < 14.13.1 | 14.13.1 | — |
| nuget | Magick.NET-Q16-arm64 | < 14.13.1 | 14.13.1 | — |
| nuget | Magick.NET-Q16-x64 | < 14.13.1 | 14.13.1 | — |
| nuget | Magick.NET-Q16-x86 | < 14.13.1 | 14.13.1 | — |
| nuget | Magick.NET-Q8-AnyCPU | < 14.13.1 | 14.13.1 | — |
| nuget | Magick.NET-Q8-OpenMP-arm64 | < 14.13.1 | 14.13.1 | — |
| nuget | Magick.NET-Q8-OpenMP-x64 | < 14.13.1 | 14.13.1 | — |
| nuget | Magick.NET-Q8-arm64 | < 14.13.1 | 14.13.1 | — |
| nuget | Magick.NET-Q8-x64 | < 14.13.1 | 14.13.1 | — |
| nuget | Magick.NET-Q8-x86 | < 14.13.1 | 14.13.1 | — |