[Git][security-tracker-team/security-tracker][master] Add CVE-2026-31853/imagemagick

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Mar 12 19:40:21 GMT 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a3667bed by Salvatore Bonaccorso at 2026-03-12T20:39:48+01:00
Add CVE-2026-31853/imagemagick

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -430,7 +430,10 @@ CVE-2026-31856 (Parse Server is an open source backend that can be deployed to a
 CVE-2026-31854 (Cursor is a code editor built for programming with AI. Prior to 2.0 ,i ...)
 	NOT-FOR-US: Cursor
 CVE-2026-31853 (ImageMagick is free and open-source software used for editing and mani ...)
-	TODO: check
+	- imagemagick 8:7.1.2.16+dfsg1-1
+	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-56jp-jfqg-f8f4
+	NOTE: https://github.com/ImageMagick/ImageMagick/commit/7936d9c7bec4bd459a8d4b5304a1a6fbf7dac0ea (7.1.2-16)
+	NOTE: https://github.com/ImageMagick/ImageMagick6/commit/fa85920aa28ee1887cc3c5d7d5272b3650d3b168 (6.9.13-41)
 CVE-2026-31852 (Jellyfin is an open-source media system. The code-quality.yml GitHub A ...)
 	- jellyfin <itp> (bug #994189)
 CVE-2026-31840 (Parse Server is an open source backend that can be deployed to any inf ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a3667bed00a5bb9b88789012e0b77f4155baca8c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a3667bed00a5bb9b88789012e0b77f4155baca8c
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260312/1dbbc267/attachment.htm>


More information about the debian-security-tracker-commits mailing list