JLSEC-2026-890

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2026/JLSEC-2026-890.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-890.json
JSON Data
https://api.osv.dev/v1/vulns/JLSEC-2026-890
Upstream
  • EUVD-2021-25590
Published
2026-07-30T16:02:27.435Z
Modified
2026-07-30T18:23:55.922002448Z
Severity
Summary
[none]
Details

ImageMagick is free software delivered as a ready-to-run binary distribution or as source code that you may use, copy, modify, and distribute in both open and proprietary applications. In affected versions and in certain cases, Postscript files could be read and written when specifically excluded by a module policy in policy.xml. ex. <policy domain="module" rights="none" pattern="PS" />. The issue has been resolved in ImageMagick 7.1.0-7 and in 6.9.12-22. Fortunately, in the wild, few users utilize the module policy and instead use the coder policy that is also our workaround recommendation: <policy domain="coder" rights="none" pattern="{PS,EPI,EPS,EPSF,EPSI}" />.

Database specific
{
    "sources": [
        {
            "id": "CVE-2021-39212",
            "imported": "2026-07-30T14:08:43.071Z",
            "html_url": "https://nvd.nist.gov/vuln/detail/CVE-2021-39212",
            "published": "2021-09-13T18:15:23.907Z",
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2021-39212",
            "modified": "2026-06-17T04:03:19.377Z",
            "database_specific": {
                "status": "Modified"
            }
        },
        {
            "id": "EUVD-2021-25590",
            "html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-25590",
            "published": "2021-09-13T00:00:00Z",
            "url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2021-25590",
            "modified": "2024-08-04T01:58:18Z",
            "imported": "2026-07-30T14:08:56.168Z"
        }
    ],
    "license": "CC-BY-4.0"
}
References

Affected packages

Julia / ImageMagick_jll

Package

Name
ImageMagick_jll
Purl
pkg:julia/ImageMagick_jll?uuid=c73af94c-d91f-53ed-93a7-00f77d67a9d7

Affected ranges

Type
SEMVER
Events
Introduced
6.9.12+0
Fixed
6.9.12+1

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-890.json"