<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T07:44:37.419209+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-09433</id>
    <title>bdu:2026-09433</title>
    <updated>2026-10-03T07:44:37.689364+00:00</updated>
    <content>bdu:2026-09433</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-09433"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329280</id>
    <title>EUVD-2026-329280</title>
    <updated>2026-10-03T07:44:37.689402+00:00</updated>
    <content>EUVD-2026-329280</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329280"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-25966</id>
    <title>fkie_cve-2026-25966</title>
    <updated>2026-10-03T07:44:37.689416+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ImageMagick is free and open-source software used for editing and manipulating digital images. The shipped "secure" security policy includes a rule intended to prevent reading/writing from standard streams. However, ImageMagick also supports fd:&lt;n&gt; pseudo-filenames (e.g., fd:0, fd:1). Prior to versions 7.1.2-15 and 6.9.13-40, this path form is not blocked by the secure policy templates, and therefore bypasses the protection goal of "no stdin/stdout." Versions 7.1.2-15 and 6.9.13-40 contain a patch by including a change to the more secure policies by default. As a workaround, add the change to one's security policy manually.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-25966"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xwc6-v6g8-pw2h</id>
    <title>GHSA-xwc6-v6g8-pw2h — ImageMagick's Security Policy Bypass through config/policy-secure.xml via "fd handler" leads to stdin/stdout access</title>
    <updated>2026-10-03T07:44:37.689451+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> NuGet: Magick.NET-Q16-AnyCPU, NuGet: Magick.NET-Q16-HDRI-AnyCPU, NuGet: Magick.NET-Q16-HDRI-OpenMP-arm64, NuGet: Magick.NET-Q16-HDRI-arm64, NuGet: Magick.NET-Q16-HDRI-x64, NuGet: Magick.NET-Q16-HDRI-x86, NuGet: Magick.NET-Q16-OpenMP-arm64, NuGet: Magick.NET-Q16-OpenMP-x64, NuGet: Magick.NET-Q16-OpenMP-x86, NuGet: Magick.NET-Q16-arm64 and 7 more</p>
<p>The shipped “secure” security policy includes a rule intended to prevent reading/writing from standard streams:</p>
<p>```xml
&lt;policy domain="path" rights="none" pattern="-"/&gt;
```</p>
<p>However, ImageMagick also supports fd:&lt;n&gt; pseudo-filenames (e.g., fd:0, fd:1). This path form is not blocked by the secure policy templates, and therefore bypasses the protection goal of “no stdin/stdout”.</p>
<p>To resolve this, users can add the following change to their security policy.</p>
<p>```xml
&lt;policy domain="path" rights="none" pattern="fd:*"/&gt;
```</p>
<p>And this will also be included in ImageMagick's more secure policies by default.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xwc6-v6g8-pw2h"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1452</id>
    <title>OESA-2026-1452 — ImageMagick security update</title>
    <updated>2026-10-03T07:44:37.689506+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP3: ImageMagick</p>
<p>Use ImageMagick to create, edit, compose, or convert bitmap images. It can read and write images in a variety of formats (over 200) including PNG, JPEG, GIF, HEIC, TIFF, DPX, EXR, WebP, Postscript, PDF, and SVG. Use ImageMagick to resize, flip, mirror, rotate, distort, shear and transform images, adjust image colors, apply various special effects, or draw text, lines, polygons, ellipses and Bézier curves.

Security Fix(es):</p>
<p>ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap information disclosure vulnerability exists in ImageMagick&amp;apos;s PSD (Adobe Photoshop) format handler. When processing a maliciously crafted PSD file containing ZIP-compressed layer data that decompresses to less than the expected size, uninitialized heap memory is leaked into the output image. Versions 7.1.2-15 and 6.9.13-40 contain a patch.(CVE-2026-24481)</p>
<p>ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, Magick fails to check for multi-layer nested mvg conversions to svg, leading to DoS. Versions 7.1.2-15 and 6.9.13-40 contain a patch.(CVE-2026-24484)</p>
<p>ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, when a PCD file does not contain a valid Sync marker, the DecodeImage() function becomes trapped in an infinite loop while searching for…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1452"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10267-1</id>
    <title>openSUSE-SU-2026:10267-1 — ImageMagick-7.1.2.15-1.1 on GA media</title>
    <updated>2026-10-03T07:44:37.689600+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ImageMagick-7.1.2.15-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10267-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:0852-1</id>
    <title>SUSE-SU-2026:0852-1 — Security update for ImageMagick</title>
    <updated>2026-10-03T07:44:37.689638+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for ImageMagick</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:0852-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-25966</id>
    <title>UBUNTU-CVE-2026-25966</title>
    <updated>2026-10-03T07:44:37.689670+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: imagemagick, Ubuntu:Pro:16.04:LTS: imagemagick, Ubuntu:Pro:18.04:LTS: imagemagick, Ubuntu:Pro:20.04:LTS: imagemagick, Ubuntu:Pro:22.04:LTS: imagemagick, Ubuntu:Pro:24.04:LTS: imagemagick, Ubuntu:25.10: imagemagick, Ubuntu:Pro:26.04:LTS: imagemagick</p>
<p>ImageMagick is free and open-source software used for editing and manipulating digital images. The shipped "secure" security policy includes a rule intended to prevent reading/writing from standard streams. However, ImageMagick also supports fd:&lt;n&gt; pseudo-filenames (e.g., fd:0, fd:1). Prior to versions 7.1.2-15 and 6.9.13-40, this path form is not blocked by the secure policy templates, and therefore bypasses the protection goal of "no stdin/stdout." Versions 7.1.2-15 and 6.9.13-40 contain a patch by including a change to the more secure policies by default. As a workaround, add the change to one's security policy manually.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-25966"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-021</id>
    <title>VDE-2026-021 — WAGO: Multiple Vulnerabilities in WAGO VC Hub</title>
    <updated>2026-10-03T07:44:37.689704+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The VC Hub incorporates the Magick.NET‑Q16‑AnyCPU component, derived from ImageMagick, to process user‑uploaded images and generate thumbnails within the projects image library. Only authenticated users with the Design Project Permission can upload images.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-021"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0484</id>
    <title>WID-SEC-W-2026-0484 — ImageMagick: Mehrere Schwachstellen</title>
    <updated>2026-10-03T07:44:37.689738+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in ImageMagick ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere nicht näher definierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0484"/>
  </entry>
</feed>
