๐Ÿ” CVE Alert

CVE-2026-103118

MEDIUM 4.3

GraphicsMagick WPG File wpg.c ExtractPostscript recursion

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was detected in GraphicsMagick up to 1.3.47. Affected by this vulnerability is the function ExtractPostscript of the file coders/wpg.c of the component WPG File Handler. Performing a manipulation results in uncontrolled recursion. The attack may be initiated remotely. The patch is named 627b5b1b2fc2. It is suggested to install a patch to address this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

CWE CWE-674 CWE-404
Vendor n/a
Product graphicsmagick
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for n/a graphicsmagick

Be the first to know when new medium vulnerabilities affecting n/a graphicsmagick are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:X/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

n/a / GraphicsMagick
1.3.0 1.3.1 1.3.2 1.3.3 1.3.4 1.3.5 1.3.6 1.3.7 1.3.8 1.3.9 1.3.10 1.3.11 1.3.12 1.3.13 1.3.14 1.3.15 1.3.16 1.3.17 1.3.18 1.3.19 1.3.20 1.3.21 1.3.22 1.3.23 1.3.24 1.3.25 1.3.26 1.3.27 1.3.28 1.3.29 1.3.30 1.3.31 1.3.32 1.3.33 1.3.34 1.3.35 1.3.36 1.3.37 1.3.38 1.3.39 1.3.40 1.3.41 1.3.42 1.3.43 1.3.44 1.3.45 1.3.46 1.3.47

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/411874 vuldb.com: https://vuldb.com/vuln/411874/cti vuldb.com: https://vuldb.com/cve/CVE-2026-103118 vuldb.com: https://vuldb.com/submit/954970 foss.heptapod.net: https://foss.heptapod.net/graphicsmagick/graphicsmagick/-/commit/627b5b1b2fc2

Credits

๐Ÿ” zzxzzb (VulDB User) VulDB CNA Team