NUGET · JULY 2026 · EARLY WARNING

ImageMagick NuGet Package Vulnerability: Use-After-Free in 8BIM Profile

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-FF5C-8X9R-8QCWSeverity: HIGH

An early warning has been issued regarding a use-after-free vulnerability in the ImageMagick NuGet package. This vulnerability reportedly occurs when identifying an image with a crafted 8BIM profile with a specific format string.

What happened

The ImageMagick NuGet package is under investigation for a use-after-free vulnerability tracked as GHSA-ff5c-8x9r-8qcw. This vulnerability appears to be triggered when the package identifies an image containing a specially crafted 8BIM profile. The specific format string used in the 8BIM profile is believed to cause the use-after-free condition.

Professional software engineers using the ImageMagick NuGet package in their projects should monitor for patches and updates from the ImageMagick maintainers. It is recommended to review the project's dependencies and assess whether the ImageMagick NuGet package is in use. If so, staying informed about any security advisories and applying updates as they become available is crucial.

For more detailed information, the primary sources should be consulted. The GitHub Security Advisories provide further context on the reported vulnerabilities in ImageMagick, including other issues such as heap buffer over-writes, policy bypasses, and memory leaks. Engineers are advised to review these advisories to understand the full scope of potential risks associated with the ImageMagick package.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If imagemagick is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats