<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:16:57 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-06712</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-06712</link>
      <description>bdu:2026-06712</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-06712</guid>
    </item>
    <item>
      <title>EUVD-2026-337449</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337449</link>
      <description>EUVD-2026-337449</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337449</guid>
    </item>
    <item>
      <title>fkie_cve-2026-25965</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-25965</link>
      <description>&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick’s path security policy is enforced on the raw filename string before the filesystem resolves it. As a result, a policy rule such as /etc/* can be bypassed by a path traversal. The OS resolves the traversal and opens the sensitive file, but the policy matcher only sees the unnormalized path and therefore allows the read. This enables local file disclosure (LFI) even when policy-secure.xml is applied. Actions to prevent reading from files have been taken in versions .7.1.2-15 and 6.9.13-40 But it make sure writing is also not possible the following should be added to one&amp;#39;s policy. This will also be included in ImageMagick&amp;#39;s more secure policies by default.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick’s path security policy is enforced on the raw filename string before the filesystem resolves it. As a result, a policy rule such as /etc/* can be bypassed by a path traversal. The OS resolves the traversal and opens the sensitive file, but the policy matcher only sees the unnormalized path and therefore allows the read. This enables local file disclosure (LFI) even when policy-secure.xml is applied. Actions to prevent reading from files have been taken in versions .7.1.2-15 and 6.9.13-40 But it make sure writing is also not possible the following should be added to one&amp;#39;s policy. This will also be included in ImageMagick&amp;#39;s more secure policies by default.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-25965</guid>
    </item>
    <item>
      <title>GHSA-8jvj-p28h-9gm7 — ImageMagick: Policy bypass through path traversal allows reading restricted content despite secured policy</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8jvj-p28h-9gm7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: Magick.NET-Q16-AnyCPU, NuGet: Magick.NET-Q16-HDRI-AnyCPU, NuGet: Magick.NET-Q16-HDRI-OpenMP-arm64, NuGet: Magick.NET-Q16-HDRI-OpenMP-x64, NuGet: Magick.NET-Q16-HDRI-arm64, NuGet: Magick.NET-Q16-HDRI-x64, NuGet: Magick.NET-Q16-HDRI-x86, NuGet: Magick.NET-Q16-OpenMP-arm64, NuGet: Magick.NET-Q16-OpenMP-x64, NuGet: Magick.NET-Q16-OpenMP-x86 and 9 more&lt;/p&gt;
&lt;p&gt;ImageMagick’s path security policy is enforced on the raw filename string before the filesystem resolves it. As a result, a policy rule such as /etc/* can be bypassed by a path traversal. The OS resolves the traversal and opens the sensitive file, but the policy matcher only sees the unnormalized path and therefore allows the read. This enables local file disclosure (LFI) even when policy-secure.xml is applied.&lt;/p&gt;
&lt;p&gt;Actions to prevent reading from files have been taken. But it make sure writing is also not possible the following should be added to your policy:&lt;/p&gt;
&lt;p&gt;```
&amp;lt;policy domain=&amp;#34;path&amp;#34; rights=&amp;#34;none&amp;#34; pattern=&amp;#34;*../*&amp;#34;/&amp;gt;
```&lt;/p&gt;
&lt;p&gt;And this will also be included in the project&amp;#39;s more secure policies by default.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: Magick.NET-Q16-AnyCPU, NuGet: Magick.NET-Q16-HDRI-AnyCPU, NuGet: Magick.NET-Q16-HDRI-OpenMP-arm64, NuGet: Magick.NET-Q16-HDRI-OpenMP-x64, NuGet: Magick.NET-Q16-HDRI-arm64, NuGet: Magick.NET-Q16-HDRI-x64, NuGet: Magick.NET-Q16-HDRI-x86, NuGet: Magick.NET-Q16-OpenMP-arm64, NuGet: Magick.NET-Q16-OpenMP-x64, NuGet: Magick.NET-Q16-OpenMP-x86 and 9 more&lt;/p&gt;
&lt;p&gt;ImageMagick’s path security policy is enforced on the raw filename string before the filesystem resolves it. As a result, a policy rule such as /etc/* can be bypassed by a path traversal. The OS resolves the traversal and opens the sensitive file, but the policy matcher only sees the unnormalized path and therefore allows the read. This enables local file disclosure (LFI) even when policy-secure.xml is applied.&lt;/p&gt;
&lt;p&gt;Actions to prevent reading from files have been taken. But it make sure writing is also not possible the following should be added to your policy:&lt;/p&gt;
&lt;p&gt;```
&amp;lt;policy domain=&amp;#34;path&amp;#34; rights=&amp;#34;none&amp;#34; pattern=&amp;#34;*../*&amp;#34;/&amp;gt;
```&lt;/p&gt;
&lt;p&gt;And this will also be included in the project&amp;#39;s more secure policies by default.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8jvj-p28h-9gm7</guid>
    </item>
    <item>
      <title>OESA-2026-1452 — ImageMagick security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1452</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: ImageMagick&lt;/p&gt;
&lt;p&gt;Use ImageMagick to create, edit, compose, or convert bitmap images. It can read and write images in a variety of formats (over 200) including PNG, JPEG, GIF, HEIC, TIFF, DPX, EXR, WebP, Postscript, PDF, and SVG. Use ImageMagick to resize, flip, mirror, rotate, distort, shear and transform images, adjust image colors, apply various special effects, or draw text, lines, polygons, ellipses and Bézier curves.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap information disclosure vulnerability exists in ImageMagick&amp;amp;apos;s PSD (Adobe Photoshop) format handler. When processing a maliciously crafted PSD file containing ZIP-compressed layer data that decompresses to less than the expected size, uninitialized heap memory is leaked into the output image. Versions 7.1.2-15 and 6.9.13-40 contain a patch.(CVE-2026-24481)&lt;/p&gt;
&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, Magick fails to check for multi-layer nested mvg conversions to svg, leading to DoS. Versions 7.1.2-15 and 6.9.13-40 contain a patch.(CVE-2026-24484)&lt;/p&gt;
&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, when a PCD file does not contain a valid Sync marker, the DecodeImage() function becomes trapped in an infinite loop while searching for…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: ImageMagick&lt;/p&gt;
&lt;p&gt;Use ImageMagick to create, edit, compose, or convert bitmap images. It can read and write images in a variety of formats (over 200) including PNG, JPEG, GIF, HEIC, TIFF, DPX, EXR, WebP, Postscript, PDF, and SVG. Use ImageMagick to resize, flip, mirror, rotate, distort, shear and transform images, adjust image colors, apply various special effects, or draw text, lines, polygons, ellipses and Bézier curves.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap information disclosure vulnerability exists in ImageMagick&amp;amp;apos;s PSD (Adobe Photoshop) format handler. When processing a maliciously crafted PSD file containing ZIP-compressed layer data that decompresses to less than the expected size, uninitialized heap memory is leaked into the output image. Versions 7.1.2-15 and 6.9.13-40 contain a patch.(CVE-2026-24481)&lt;/p&gt;
&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, Magick fails to check for multi-layer nested mvg conversions to svg, leading to DoS. Versions 7.1.2-15 and 6.9.13-40 contain a patch.(CVE-2026-24484)&lt;/p&gt;
&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, when a PCD file does not contain a valid Sync marker, the DecodeImage() function becomes trapped in an infinite loop while searching for…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1452</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10267-1 — ImageMagick-7.1.2.15-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10267-1</link>
      <description>&lt;p&gt;ImageMagick-7.1.2.15-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ImageMagick-7.1.2.15-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10267-1</guid>
    </item>
    <item>
      <title>RHSA-2026:5573 — Red Hat Security Advisory: ImageMagick security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:5573</link>
      <description>&lt;p&gt;ImageMagick: ImageMagick: Local File Disclosure via Path Traversal ImageMagick: Memory allocation with excessive without limits in the internal SVG decoder&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ImageMagick: ImageMagick: Local File Disclosure via Path Traversal ImageMagick: Memory allocation with excessive without limits in the internal SVG decoder&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:5573</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:0852-1 — Security update for ImageMagick</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:0852-1</link>
      <description>&lt;p&gt;Security update for ImageMagick&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for ImageMagick&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:0852-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-25965</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-25965</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: imagemagick, Ubuntu:Pro:16.04:LTS: imagemagick, Ubuntu:Pro:18.04:LTS: imagemagick, Ubuntu:Pro:20.04:LTS: imagemagick, Ubuntu:Pro:22.04:LTS: imagemagick, Ubuntu:Pro:24.04:LTS: imagemagick, Ubuntu:25.10: imagemagick&lt;/p&gt;
&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick’s path security policy is enforced on the raw filename string before the filesystem resolves it. As a result, a policy rule such as /etc/* can be bypassed by a path traversal. The OS resolves the traversal and opens the sensitive file, but the policy matcher only sees the unnormalized path and therefore allows the read. This enables local file disclosure (LFI) even when policy-secure.xml is applied. Actions to prevent reading from files have been taken in versions .7.1.2-15 and 6.9.13-40 But it make sure writing is also not possible the following should be added to one&amp;#39;s policy. This will also be included in ImageMagick&amp;#39;s more secure policies by default.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: imagemagick, Ubuntu:Pro:16.04:LTS: imagemagick, Ubuntu:Pro:18.04:LTS: imagemagick, Ubuntu:Pro:20.04:LTS: imagemagick, Ubuntu:Pro:22.04:LTS: imagemagick, Ubuntu:Pro:24.04:LTS: imagemagick, Ubuntu:25.10: imagemagick&lt;/p&gt;
&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick’s path security policy is enforced on the raw filename string before the filesystem resolves it. As a result, a policy rule such as /etc/* can be bypassed by a path traversal. The OS resolves the traversal and opens the sensitive file, but the policy matcher only sees the unnormalized path and therefore allows the read. This enables local file disclosure (LFI) even when policy-secure.xml is applied. Actions to prevent reading from files have been taken in versions .7.1.2-15 and 6.9.13-40 But it make sure writing is also not possible the following should be added to one&amp;#39;s policy. This will also be included in ImageMagick&amp;#39;s more secure policies by default.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-25965</guid>
    </item>
    <item>
      <title>VDE-2026-021 — WAGO: Multiple Vulnerabilities in WAGO VC Hub</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-021</link>
      <description>&lt;p&gt;The VC Hub incorporates the Magick.NET‑Q16‑AnyCPU component, derived from ImageMagick, to process user‑uploaded images and generate thumbnails within the projects image library. Only authenticated users with the Design Project Permission can upload images.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The VC Hub incorporates the Magick.NET‑Q16‑AnyCPU component, derived from ImageMagick, to process user‑uploaded images and generate thumbnails within the projects image library. Only authenticated users with the Design Project Permission can upload images.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-021</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0484 — ImageMagick: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0484</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in ImageMagick ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere nicht näher definierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in ImageMagick ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere nicht näher definierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0484</guid>
    </item>
  </channel>
</rss>
