CVE-2026-103118
Last modified
CVE-2026-103118 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. A vulnerability was detected in GraphicsMagick up to 1.3.47. Affected by this vulnerability is the function ExtractPostscript of the file coders/wpg.c of the component WPG File Handler.
Description
A vulnerability was detected in GraphicsMagick up to 1.3.47. Affected by this vulnerability is the function ExtractPostscript of the file coders/wpg.c of the component WPG File Handler. Performing a manipulation results in uncontrolled recursion. The attack may be initiated remotely. The patch is named 627b5b1b2fc2. It is suggested to install a patch to address this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| — | GraphicsMagick | 1.3.0; 1.3.1; 1.3.2; 1.3.3; 1.3.4; 1.3.5; 1.3.6; 1.3.7; 1.3.8; 1.3.9; 1.3.10; 1.3.11; 1.3.12; 1.3.13; 1.3.14; 1.3.15; 1.3.16; 1.3.17; 1.3.18; 1.3.19; 1.3.20; 1.3.21; 1.3.22; 1.3.23; 1.3.24; 1.3.25; 1.3.26; 1.3.27; 1.3.28; 1.3.29; 1.3.30; 1.3.31; 1.3.32; 1.3.33; 1.3.34; 1.3.35; 1.3.36; 1.3.37; 1.3.38; 1.3.39; 1.3.40; 1.3.41; 1.3.42; 1.3.43; 1.3.44; 1.3.45; 1.3.46; 1.3.47 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-103118?
How severe is CVE-2026-103118?
How do I fix CVE-2026-103118?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-103111PCRE2 before 10.49, when there is an attacker-controlled reg…7.6
- CVE-2026-103113A vulnerability was determined in OS4ED openSIS-Classic up t…4.7
- CVE-2026-103114A vulnerability was identified in OS4ED openSIS-Classic up t…6.3
- CVE-2026-103115A security flaw has been discovered in OS4ED openSIS-Classic…6.3
- CVE-2026-103116A weakness has been identified in OS4ED openSIS-Classic up t…6.3
- CVE-2026-103117A security vulnerability has been detected in OS4ED openSIS-…4.7
- CVE-2026-1032The Conditional Menus plugin for WordPress is vulnerable to …4.3
- CVE-2026-103222A vulnerability was determined in Blosc C-Blosc2 up to 3.3.2…5.6
- CVE-2026-103226A vulnerability was identified in Artifex Ghostscript up to …6.3
- CVE-2026-103227A weakness has been identified in GPAC up to 26.07.0. Affect…6.3
- CVE-2026-103229A vulnerability was found in AdithyaYelloju Restaurant-Manag…7.3
- CVE-2026-103230A vulnerability was determined in AdithyaYelloju Restaurant-…7.3
Are you affected by CVE-2026-103118?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
