ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, an off by one error in the MSL decoder could result in a crash when a malicous MSL file is read. This issue has been fixed in version 7.1.2-19.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40312.json",
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-193"
]
}{
"source": "REFERENCES"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "7.1.2-19"
}
],
"cpe": "cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40312.json"
[
{
"deprecated": false,
"id": "CVE-2026-40312-7aa91b50",
"digest": {
"line_hashes": [
"340036835030325694410068937464149529866",
"338267870035362876854652464562020582284",
"192617517728642521381215505057774278205",
"290839537236692204189782044616902551758"
],
"threshold": 0.9
},
"signature_type": "Line",
"source": "https://github.com/imagemagick/imagemagick/commit/2a06c7be3bba3326caf8b7a8d1fa2e0d4b88998d",
"signature_version": "v1",
"target": {
"file": "coders/msl.c"
}
},
{
"deprecated": false,
"id": "CVE-2026-40312-bf6d1264",
"digest": {
"length": 1727.0,
"function_hash": "250068752826211052229380137769889067221"
},
"signature_type": "Function",
"source": "https://github.com/imagemagick/imagemagick/commit/2a06c7be3bba3326caf8b7a8d1fa2e0d4b88998d",
"signature_version": "v1",
"target": {
"function": "MSLPushImage",
"file": "coders/msl.c"
}
}
]
"2026-08-07T21:27:13Z"