ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, the -sample operation has an out of bounds read when an specific offset is set through the sample:offset define that could lead to an out of bounds read. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.
{
"cna_assigner": "GitHub_M",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"fixed": "6.9.13-44"
}
]
}
],
"cwe_ids": [
"CWE-125"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33905.json"
}{
"source": [
"CPE_FIELD",
"REFERENCES"
],
"cpe": "cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "7.0.0-0"
},
{
"fixed": "7.1.2-19"
}
]
}[
{
"id": "CVE-2026-33905-1bb74a61",
"target": {
"file": "MagickCore/resize.c"
},
"source": "https://github.com/imagemagick/imagemagick/commit/cca607366fb38c2dde019a9088b8415ffba3a835",
"signature_version": "v1",
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"75353777190922650986589350666566161148",
"168810957652386007583810245357325865902",
"298291704088744731588986990995350813639",
"49883425011972125027242162006965839671",
"333430954526771431200408099834212434546",
"199919326994846573640797641055103255902",
"65481676736574339415028663426205323558",
"125022824201968453462846498831503601520",
"327074900473275078904635195717959442248",
"112126613899572954043402514215727730229",
"326805960093790897855271575991009373114",
"160709059155545326914450602698396922145",
"124031028531303367306735944836927726298",
"163187243794285266654394062463724856516",
"165768064205504916036856802556753812675",
"171186224640843187688500298937550908056",
"235607285608388278790754231694679612496",
"75174162085775494171463861324181389847",
"42528349163390276829902479324166492497",
"2281082130256360009402312311984211357",
"309605546771417831049696415938958117832",
"236535404780514739926410649775302201824",
"24350019423169121873254852670683541753",
"233893322867894566751344453475158633621",
"266083761662466268793945800710849031950",
"34126522730597815224129088946133302501",
"177573105693757012722341707745295075881",
"79282826903506870212029662610831627247",
"254771188344730444561883048789558071161",
"283387280385507759415653724904138527780",
"205447635761826434797895177220391706459",
"261437366764002593652083582014752404760",
"100942336901027185421116061763544445816",
"249465038285040806983750815963535853236",
"93562076184703298084531683071525220212",
"188142407031559327732223284501254904423",
"158112222799991908703404913410938600896",
"143969097724735260078485389630473730008",
"263612602078689884311467136427121071573",
"163674659670410507562555870509876331226",
"284075807480579101990668815456432197594",
"214521891362762565858246865736783213688",
"302460831880935745433555741030749316738",
"304878671196282561598664867935444068708",
"285315876672327629972223791046308414625",
"103937916920357907560472503353985780771",
"139135771233175165786430431484927965187",
"32504690289771505170796477576310492985",
"91931886500725769254070561312668796942",
"140506375989908807340217718735762684889",
"107321087126679171716718192386284713142",
"139160717508386088602939013055627053967",
"295836602979927025874994603524955757542",
"162692681240912516627001018114202986646",
"132992727382538848926473426501264886035",
"15516685555545536192775570474544316358",
"129542385650532874668008687763760114668"
],
"threshold": 0.9
}
},
{
"id": "CVE-2026-33905-f9ae6cc1",
"target": {
"function": "SampleImage",
"file": "MagickCore/resize.c"
},
"source": "https://github.com/imagemagick/imagemagick/commit/cca607366fb38c2dde019a9088b8415ffba3a835",
"signature_version": "v1",
"signature_type": "Function",
"deprecated": false,
"digest": {
"function_hash": "63779533176416113343569052222055267307",
"length": 3359.0
}
}
]
"2026-05-23T22:36:10Z"
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-33905.json"
{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "6.9.13-44"
}
]
}