The distributed pixel cache was originally designed to operate without a challenge–response authentication model. However, given today’s heightened security expectations, we have changed our implementation.
Update Magick.NET-Q16-AnyCPU to 14.12.0; Magick.NET-Q16-arm64 to 14.12.0; Magick.NET-Q16-HDRI-AnyCPU to 14.12.0; Magick.NET-Q16-HDRI-arm64 to 14.12.0; Magick.NET-Q16-HDRI-OpenMP-arm64 to 14.12.0; Magick.NET-Q16-HDRI-x64 to 14.12.0; Magick.NET-Q16-HDRI-x86 to 14.12.0; Magick.NET-Q16-OpenMP-arm64 to 14.12.0; Magick.NET-Q16-OpenMP-x64 to 14.12.0; Magick.NET-Q16-x64 to 14.12.0; Magick.NET-Q16-x86 to 14.12.0; Magick.NET-Q8-AnyCPU to 14.12.0; Magick.NET-Q8-arm64 to 14.12.0; Magick.NET-Q8-OpenMP-arm64 to 14.12.0; Magick.NET-Q8-OpenMP-x64 to 14.12.0; Magick.NET-Q8-x64 to 14.12.0; Magick.NET-Q8-x86 to 14.12.0 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanImageMagick: Information Disclosure in distributed pixel cache server because it is not using a challenge–response authentication model affects Magick.NET-Q16-AnyCPU (nuget), Magick.NET-Q16-arm64 (nuget), Magick.NET-Q16-HDRI-AnyCPU (nuget), Magick.NET-Q16-HDRI-arm64 (nuget), Magick.NET-Q16-HDRI-OpenMP-arm64 (nuget), Magick.NET-Q16-HDRI-x64 (nuget), Magick.NET-Q16-HDRI-x86 (nuget), Magick.NET-Q16-OpenMP-arm64 (nuget), Magick.NET-Q16-OpenMP-x64 (nuget), Magick.NET-Q16-x64 (nuget), Magick.NET-Q16-x86 (nuget), Magick.NET-Q8-AnyCPU (nuget), Magick.NET-Q8-arm64 (nuget), Magick.NET-Q8-OpenMP-arm64 (nuget), Magick.NET-Q8-OpenMP-x64 (nuget), Magick.NET-Q8-x64 (nuget), Magick.NET-Q8-x86 (nuget). Severity is medium. The distributed pixel cache was originally designed to operate without a challenge–response authentication model. However, given today’s heightened security expectations, we have changed our implementation.
AI coding agents often install or upgrade packages automatically in nuget. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
The distributed pixel cache was originally designed to operate without a challenge–response authentication model. However, given today’s heightened security expectations, we have changed our implementation.
Update Magick.NET-Q16-AnyCPU to 14.12.0; Magick.NET-Q16-arm64 to 14.12.0; Magick.NET-Q16-HDRI-AnyCPU to 14.12.0; Magick.NET-Q16-HDRI-arm64 to 14.12.0; Magick.NET-Q16-HDRI-OpenMP-arm64 to 14.12.0; Magick.NET-Q16-HDRI-x64 to 14.12.0; Magick.NET-Q16-HDRI-x86 to 14.12.0; Magick.NET-Q16-OpenMP-arm64 to 14.12.0; Magick.NET-Q16-OpenMP-x64 to 14.12.0; Magick.NET-Q16-x64 to 14.12.0; Magick.NET-Q16-x86 to 14.12.0; Magick.NET-Q8-AnyCPU to 14.12.0; Magick.NET-Q8-arm64 to 14.12.0; Magick.NET-Q8-OpenMP-arm64 to 14.12.0; Magick.NET-Q8-OpenMP-x64 to 14.12.0; Magick.NET-Q8-x64 to 14.12.0; Magick.NET-Q8-x86 to 14.12.0 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanImageMagick: Information Disclosure in distributed pixel cache server because it is not using a challenge–response authentication model affects Magick.NET-Q16-AnyCPU (nuget), Magick.NET-Q16-arm64 (nuget), Magick.NET-Q16-HDRI-AnyCPU (nuget), Magick.NET-Q16-HDRI-arm64 (nuget), Magick.NET-Q16-HDRI-OpenMP-arm64 (nuget), Magick.NET-Q16-HDRI-x64 (nuget), Magick.NET-Q16-HDRI-x86 (nuget), Magick.NET-Q16-OpenMP-arm64 (nuget), Magick.NET-Q16-OpenMP-x64 (nuget), Magick.NET-Q16-x64 (nuget), Magick.NET-Q16-x86 (nuget), Magick.NET-Q8-AnyCPU (nuget), Magick.NET-Q8-arm64 (nuget), Magick.NET-Q8-OpenMP-arm64 (nuget), Magick.NET-Q8-OpenMP-x64 (nuget), Magick.NET-Q8-x64 (nuget), Magick.NET-Q8-x86 (nuget). Severity is medium. The distributed pixel cache was originally designed to operate without a challenge–response authentication model. However, given today’s heightened security expectations, we have changed our implementation.
AI coding agents often install or upgrade packages automatically in nuget. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Magick.NET-Q16-AnyCPUnuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q16-arm64nuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q16-HDRI-AnyCPUnuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q16-HDRI-arm64nuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q16-HDRI-OpenMP-arm64nuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q16-HDRI-x64nuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q16-HDRI-x86nuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q16-OpenMP-arm64nuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q16-OpenMP-x64nuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q16-x64nuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q16-x86nuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q8-AnyCPUnuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q8-arm64nuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q8-OpenMP-arm64nuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q8-OpenMP-x64nuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q8-x64nuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q8-x86nuget | <14.12.0 | 14.12.0 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| Package | Affected range | Fixed version |
|---|---|---|
| Magick.NET-Q16-AnyCPUnuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q16-arm64nuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q16-HDRI-AnyCPUnuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q16-HDRI-arm64nuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q16-HDRI-OpenMP-arm64nuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q16-HDRI-x64nuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q16-HDRI-x86nuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q16-OpenMP-arm64nuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q16-OpenMP-x64nuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q16-x64nuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q16-x86nuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q8-AnyCPUnuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q8-arm64nuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q8-OpenMP-arm64nuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q8-OpenMP-x64nuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q8-x64nuget | <14.12.0 | 14.12.0 |
| Magick.NET-Q8-x86nuget | <14.12.0 | 14.12.0 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard