{
  "threat_severity" : "Important",
  "public_date" : "2026-04-13T20:56:12Z",
  "bugzilla" : {
    "description" : "ImageMagick: Magick.NET: ImageMagick: Denial of Service due to heap buffer overflow in MVG decoder",
    "id" : "2458023",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2458023"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "status" : "draft"
  },
  "cwe" : "CWE-787",
  "details" : [ "A flaw was found in ImageMagick. A remote attacker could exploit a heap buffer overflow vulnerability in the MVG decoder by processing a specially crafted image file. This vulnerability allows for an out-of-bounds write, which could lead to a Denial of Service (DoS) for the affected system." ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Out of support scope",
    "package_name" : "ImageMagick",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Out of support scope",
    "package_name" : "ImageMagick",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-33901\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33901\nhttps://github.com/ImageMagick/ImageMagick/commit/4c72003e9e54a4ebaa938d239e75f5d285527ebe\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-x9h5-r9v2-vcww\nhttps://github.com/dlemstra/Magick.NET/releases/tag/14.12.0" ],
  "name" : "CVE-2026-33901",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}