CVE-2026-103118

MEDIUMCVSS 4.3/10

Last modified

CVE-2026-103118 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. A vulnerability was detected in GraphicsMagick up to 1.3.47. Affected by this vulnerability is the function ExtractPostscript of the file coders/wpg.c of the component WPG File Handler.

Description

A vulnerability was detected in GraphicsMagick up to 1.3.47. Affected by this vulnerability is the function ExtractPostscript of the file coders/wpg.c of the component WPG File Handler. Performing a manipulation results in uncontrolled recursion. The attack may be initiated remotely. The patch is named 627b5b1b2fc2. It is suggested to install a patch to address this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

Metrics

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
—GraphicsMagick1.3.0; 1.3.1; 1.3.2; 1.3.3; 1.3.4; 1.3.5; 1.3.6; 1.3.7; 1.3.8; 1.3.9; 1.3.10; 1.3.11; 1.3.12; 1.3.13; 1.3.14; 1.3.15; 1.3.16; 1.3.17; 1.3.18; 1.3.19; 1.3.20; 1.3.21; 1.3.22; 1.3.23; 1.3.24; 1.3.25; 1.3.26; 1.3.27; 1.3.28; 1.3.29; 1.3.30; 1.3.31; 1.3.32; 1.3.33; 1.3.34; 1.3.35; 1.3.36; 1.3.37; 1.3.38; 1.3.39; 1.3.40; 1.3.41; 1.3.42; 1.3.43; 1.3.44; 1.3.45; 1.3.46; 1.3.47

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2026-103118?
A vulnerability was detected in GraphicsMagick up to 1.3.47. Affected by this vulnerability is the function ExtractPostscript of the file coders/wpg.c of the component WPG File Handler. Performing a manipulation results in uncontrolled recursion. The attack may be initiated remotely. The patch is named 627b5b1b2fc2. It is suggested to install a patch to address this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
How severe is CVE-2026-103118?
CVE-2026-103118 has a CVSS score of 4.3/10 (MEDIUM severity).
How do I fix CVE-2026-103118?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-103118?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST