Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.5 CVE-2026-49219

ImageMagick: Policy Bypass can read disallowed files_CVE-2026-49219

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, an incorre...

ImageMagick ImageMagick < 6.9.13-48 CVE
HIGH 7.5 CVE-2026-49218

ImageMagick: Policy Bypass in DCM decoder could result in image with invalid dimensions_CVE-2026-49218

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing ...

ImageMagick ImageMagick < 6.9.13-48 CVE
MEDIUM 5.9 CVE-2026-48994

ImageMagick: Heap Buffer Over-Write in MAT decoder on 32-bit systems_CVE-2026-48994

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing ...

ImageMagick ImageMagick < 6.9.13-48 CVE
MEDIUM 5.5 CVE-2026-48734

ImageMagick: Stack Overflow in MVG decoder_CVE-2026-48734

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-49 and 7.1.2-24, a crafted ...

ImageMagick ImageMagick < 6.9.13-49 CVE
MEDIUM 4.7 CVE-2026-48733

ImageMagick: Infinite Loop in subimage-search with crafted image_CVE-2026-48733

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-49 and 7.1.2-24, an infinit...

ImageMagick ImageMagick < 6.9.13-49 CVE
MEDIUM 5.5 CVE-2026-48724

ImageMagick: Heap Buffer Underwrite in Floyd-Steinberg depth dithering_CVE-2026-48724

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-24, when using an image with ...

ImageMagick ImageMagick < 7.1.2-24 CVE
MEDIUM 5.7 CVE-2026-47734

Dulwich has unbounded memory allocation in receive-pack from crafted thin packs_CVE-2026-47734

Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.1.0 and prior to version 1.2.5, a client with ...

jelmer dulwich >= 0.1.0, < 1.2.5 CVE
LOW 3.3 CVE-2026-47712

Dulwich doesn’t sanitize commit subjects in `porcelain.format_patch`_CVE-2026-47712

Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to version 1.2.5, dulwich.porce...

jelmer dulwich >= 0.24.0, < 1.2.5 CVE
MEDIUM 6.5 CVE-2026-47213

BoxLite: Timeout Bypass Vulnerability_CVE-2026-47213

Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untruste...

boxlite-ai boxlite <= 0.8.2 CVE
MEDIUM 5.7 CVE-2026-47166

ImageMagick: Heap Buffer Over-Read in distributed pixel cache server_CVE-2026-47166

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacke...

ImageMagick ImageMagick < 6.9.13-48 CVE