Medium · CVSS 5.3CVE-2026-45664GHSA-G5MF-WQQ5-VWG6
ImageMagick: Policy Bypass in MNG coder could
Answer in brief
CVE-2026-45664 records a Medium severity (CVSS 5.3) security vulnerability in ImageMagick: Policy Bypass in MNG coder could. The source record does not mark it as known exploited. 18 affected packages are mapped in the feed.
Published May 18, 2026Updated Jul 15, 2026Source checked Jul 18, 2026
Medium · CVSS 5.3CVE-2026-45664GHSA-G5MF-WQQ5-VWG6
ImageMagick: Policy Bypass in MNG coder could
Answer in brief
CVE-2026-45664 records a Medium severity (CVSS 5.3) security vulnerability in ImageMagick: Policy Bypass in MNG coder could. The source record does not mark it as known exploited. 18 affected packages are mapped in the feed.
Published May 18, 2026Updated Jul 15, 2026Source checked Jul 18, 2026
Update Magick.NET-Q16-AnyCPU to 14.13.1; Magick.NET-Q16-arm64 to 14.13.1; Magick.NET-Q16-HDRI-AnyCPU to 14.13.1; Magick.NET-Q16-HDRI-arm64 to 14.13.1; Magick.NET-Q16-HDRI-OpenMP-arm64 to 14.13.1; Magick.NET-Q16-HDRI-OpenMP-x64 to 14.13.1; Magick.NET-Q16-HDRI-x64 to 14.13.1; Magick.NET-Q16-HDRI-x86 to 14.13.1; Magick.NET-Q16-OpenMP-arm64 to 14.13.1; Magick.NET-Q16-OpenMP-x64 to 14.13.1; Magick.NET-Q16-x64 to 14.13.1; Magick.NET-Q16-x86 to 14.13.1; Magick.NET-Q8-AnyCPU to 14.13.1; Magick.NET-Q8-arm64 to 14.13.1; Magick.NET-Q8-OpenMP-arm64 to 14.13.1; Magick.NET-Q8-OpenMP-x64 to 14.13.1; Magick.NET-Q8-x64 to 14.13.1; Magick.NET-Q8-x86 to 14.13.1 if you use the affected versions. Test the change in a non-production environment first.
1Check lockfiles and deployed manifests for Magick.NET-Q16-AnyCPU, Magick.NET-Q16-arm64, Magick.NET-Q16-HDRI-AnyCPU.
2Update Magick.NET-Q16-AnyCPU to 14.13.1; Magick.NET-Q16-arm64 to 14.13.1; Magick.NET-Q16-HDRI-AnyCPU to 14.13.1; Magick.NET-Q16-HDRI-arm64 to 14.13.1; Magick.NET-Q16-HDRI-OpenMP-arm64 to 14.13.1; Magick.NET-Q16-HDRI-OpenMP-x64 to 14.13.1; Magick.NET-Q16-HDRI-x64 to 14.13.1; Magick.NET-Q16-HDRI-x86 to 14.13.1; Magick.NET-Q16-OpenMP-arm64 to 14.13.1; Magick.NET-Q16-OpenMP-x64 to 14.13.1; Magick.NET-Q16-x64 to 14.13.1; Magick.NET-Q16-x86 to 14.13.1; Magick.NET-Q8-AnyCPU to 14.13.1; Magick.NET-Q8-arm64 to 14.13.1; Magick.NET-Q8-OpenMP-arm64 to 14.13.1; Magick.NET-Q8-OpenMP-x64 to 14.13.1; Magick.NET-Q8-x64 to 14.13.1; Magick.NET-Q8-x86 to 14.13.1 if you use the affected versions. Test the change in a non-production environment first.
3Retest the affected application or service after the dependency change and record the verification date.
Local check
hol-guard supply-chain scan
Why this matters
Vulnerability describes the vulnerability class recorded for this advisory. The current record does not mark CVE-2026-45664 as known exploited; continue to monitor the source for status changes. The feed includes package mappings that can be checked against lockfiles and deployed manifests.
CVE-2026-45664 records a Medium severity (CVSS 5.3) security vulnerability in ImageMagick: Policy Bypass in MNG coder could. The source record does not mark it as known exploited. 18 affected packages are mapped in the feed.
Is CVE-2026-45664 known to be exploited?
The source record does not mark it as known exploited.
What should defenders do about CVE-2026-45664?
Check lockfiles and deployed manifests for Magick.NET-Q16-AnyCPU, Magick.NET-Q16-arm64, Magick.NET-Q16-HDRI-AnyCPU.
Keep this signal in your Guard workflow.
HOL Guard can help your team review package activity against supported protection paths.
Update Magick.NET-Q16-AnyCPU to 14.13.1; Magick.NET-Q16-arm64 to 14.13.1; Magick.NET-Q16-HDRI-AnyCPU to 14.13.1; Magick.NET-Q16-HDRI-arm64 to 14.13.1; Magick.NET-Q16-HDRI-OpenMP-arm64 to 14.13.1; Magick.NET-Q16-HDRI-OpenMP-x64 to 14.13.1; Magick.NET-Q16-HDRI-x64 to 14.13.1; Magick.NET-Q16-HDRI-x86 to 14.13.1; Magick.NET-Q16-OpenMP-arm64 to 14.13.1; Magick.NET-Q16-OpenMP-x64 to 14.13.1; Magick.NET-Q16-x64 to 14.13.1; Magick.NET-Q16-x86 to 14.13.1; Magick.NET-Q8-AnyCPU to 14.13.1; Magick.NET-Q8-arm64 to 14.13.1; Magick.NET-Q8-OpenMP-arm64 to 14.13.1; Magick.NET-Q8-OpenMP-x64 to 14.13.1; Magick.NET-Q8-x64 to 14.13.1; Magick.NET-Q8-x86 to 14.13.1 if you use the affected versions. Test the change in a non-production environment first.
1Check lockfiles and deployed manifests for Magick.NET-Q16-AnyCPU, Magick.NET-Q16-arm64, Magick.NET-Q16-HDRI-AnyCPU.
2Update Magick.NET-Q16-AnyCPU to 14.13.1; Magick.NET-Q16-arm64 to 14.13.1; Magick.NET-Q16-HDRI-AnyCPU to 14.13.1; Magick.NET-Q16-HDRI-arm64 to 14.13.1; Magick.NET-Q16-HDRI-OpenMP-arm64 to 14.13.1; Magick.NET-Q16-HDRI-OpenMP-x64 to 14.13.1; Magick.NET-Q16-HDRI-x64 to 14.13.1; Magick.NET-Q16-HDRI-x86 to 14.13.1; Magick.NET-Q16-OpenMP-arm64 to 14.13.1; Magick.NET-Q16-OpenMP-x64 to 14.13.1; Magick.NET-Q16-x64 to 14.13.1; Magick.NET-Q16-x86 to 14.13.1; Magick.NET-Q8-AnyCPU to 14.13.1; Magick.NET-Q8-arm64 to 14.13.1; Magick.NET-Q8-OpenMP-arm64 to 14.13.1; Magick.NET-Q8-OpenMP-x64 to 14.13.1; Magick.NET-Q8-x64 to 14.13.1; Magick.NET-Q8-x86 to 14.13.1 if you use the affected versions. Test the change in a non-production environment first.
3Retest the affected application or service after the dependency change and record the verification date.
Local check
hol-guard supply-chain scan
Why this matters
Vulnerability describes the vulnerability class recorded for this advisory. The current record does not mark CVE-2026-45664 as known exploited; continue to monitor the source for status changes. The feed includes package mappings that can be checked against lockfiles and deployed manifests.
CVE-2026-45664 records a Medium severity (CVSS 5.3) security vulnerability in ImageMagick: Policy Bypass in MNG coder could. The source record does not mark it as known exploited. 18 affected packages are mapped in the feed.
Is CVE-2026-45664 known to be exploited?
The source record does not mark it as known exploited.
What should defenders do about CVE-2026-45664?
Check lockfiles and deployed manifests for Magick.NET-Q16-AnyCPU, Magick.NET-Q16-arm64, Magick.NET-Q16-HDRI-AnyCPU.
Keep this signal in your Guard workflow.
HOL Guard can help your team review package activity against supported protection paths.
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, because of a missing check in the MNG coder it would be possible to read more images than the list limit policy would allow resulting in excessive resource use. This issue has been patched in versions 6.9.13-47 and 7.1.2-22.
<14.13.1
14.13.1
Magick.NET-Q16-HDRI-x86nuget
<14.13.1
14.13.1
Magick.NET-Q16-OpenMP-arm64nuget
<14.13.1
14.13.1
Magick.NET-Q16-OpenMP-x64nuget
<14.13.1
14.13.1
Magick.NET-Q16-x64nuget
<14.13.1
14.13.1
Magick.NET-Q16-x86nuget
<14.13.1
14.13.1
Magick.NET-Q8-AnyCPUnuget
<14.13.1
14.13.1
Magick.NET-Q8-arm64nuget
<14.13.1
14.13.1
Magick.NET-Q8-OpenMP-arm64nuget
<14.13.1
14.13.1
Magick.NET-Q8-OpenMP-x64nuget
<14.13.1
14.13.1
Magick.NET-Q8-x64nuget
<14.13.1
14.13.1
Magick.NET-Q8-x86nuget
<14.13.1
14.13.1
Fixed versions are reported by the source feed; confirm compatibility before updating.
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, because of a missing check in the MNG coder it would be possible to read more images than the list limit policy would allow resulting in excessive resource use. This issue has been patched in versions 6.9.13-47 and 7.1.2-22.