ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, Magick frees the memory of the XML tree via the DestroyXMLTree() function; however, this process is executed recursively with no depth limit imposed. When Magick processes an XML file with deeply nested structures, it will exhaust the stack memory, resulting in a Denial of Service (DoS) attack. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.
{
"cwe_ids": [
"CWE-674"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33908.json",
"cna_assigner": "GitHub_M",
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "6.9.13-44"
}
],
"source": "AFFECTED_FIELD"
}
]
}{
"source": "REFERENCES"
}
{
"cpe": "cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "7.0.0-0"
},
{
"fixed": "7.1.2-19"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
{
"cpe": "cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "6.9.13-44"
}
],
"source": "CPE_RANGE"
}
"2026-08-07T21:53:39Z"
[
{
"id": "CVE-2026-33908-043d0021",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 216.0,
"function_hash": "295300739904292386346055571970138625596"
},
"source": "https://github.com/imagemagick/imagemagick/commit/ccdc01180276aa2cb3d4a32a611aa4f417061cd8",
"target": {
"function": "DestroyXMLTreeChild",
"file": "MagickCore/xml-tree.c"
}
},
{
"id": "CVE-2026-33908-5d5a58d1",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 216.0,
"function_hash": "295300739904292386346055571970138625596"
},
"source": "https://github.com/imagemagick/imagemagick/commit/ccdc01180276aa2cb3d4a32a611aa4f417061cd8",
"target": {
"function": "DestroyXMLTreeOrdered",
"file": "MagickCore/xml-tree.c"
}
},
{
"id": "CVE-2026-33908-8fc63fc1",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"251965278907910284562728412617247595460",
"125783940852337411827244773200244873441",
"89745744823702413711736704370765186733",
"12104191264893103840029361512324434655",
"148683637230523068268264121279388733728",
"15623504406316466914492481709812307183",
"249938129332224223229880103380738955061",
"60009568961997337191680974042479136718",
"9575059157144660003227278131615563892",
"294621667104522789571064191936251871863",
"197369952607673599622273015835714555450",
"214079324521069853910131143515596360726",
"231219457208224611113807077188378916861",
"190996981612061938363300584147928652181",
"303257371347393863110152241579264054830",
"221830763171567203299034780150593191821",
"305365793369850703031676904342027610175",
"181211849120644374075474776859371313716",
"160875778419644315492519900111949665995",
"314382480264478351975329546074951459249",
"50794497953892452087380366493006933454",
"66388387674602598358834662821236586456",
"327604715919331707731268027003178541284",
"169484852131306698124067470699913203815",
"212431178780079949658773369947407845863",
"172773671607198574143260891997117907563",
"116264689020524320906066842551958669195",
"162163889439495426518190196002666313478",
"145145769868183651066378057329584225126",
"203415101265560406258219972688484267863",
"83462898112693603038699642759477770994",
"208158428049100612392172313625754461698",
"205491494455416900881922384581646181748",
"313016540161695283761107475183768444158",
"169392879998560683528201268202752067587",
"153696683753316599126305047570386412199",
"96389978182805008578073407147447230820",
"81846799752772609577063891674320310276",
"145383157710166395867560815936275103134",
"167602623280447616254818016392810098494",
"182348959395289385751624162770685129696",
"296876552800886180971715151224940587213",
"97029017438467471348019877939766937452",
"39704186990307881368444997120319828881",
"154010989025984481124155157051220936570",
"146693668924117573775767632552888961091",
"291316334840228410865749610626882808812",
"133227861011603043717952721486728561734",
"22765962271286264183658488381295102836",
"116821118817998843347944954880388396302",
"17801489594855000023715254158552174773",
"59432428163109008048808841079083127959"
]
},
"source": "https://github.com/imagemagick/imagemagick/commit/ccdc01180276aa2cb3d4a32a611aa4f417061cd8",
"target": {
"file": "MagickCore/xml-tree.c"
}
},
{
"id": "CVE-2026-33908-c8b8966f",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 584.0,
"function_hash": "306335164758831549617962293487320847474"
},
"source": "https://github.com/imagemagick/imagemagick/commit/ccdc01180276aa2cb3d4a32a611aa4f417061cd8",
"target": {
"function": "DestroyXMLTree",
"file": "MagickCore/xml-tree.c"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33908.json"