medium · CVSS v3 4.3 · CVSS v4 5.3
CVE-2026-103118
GraphicsMagick up to 1.3.47 has a recursion vulnerability in the ExtractPostscript function of the WPG File Handler. A remote attacker can t
Overview
GraphicsMagick up to 1.3.47 has a recursion vulnerability in the ExtractPostscript function of the WPG File Handler. A remote attacker can trigger uncontrolled recursion, potentially exhausting the stack and causing a denial of service. The issue is fixed in newer releases.
Description
A vulnerability was detected in GraphicsMagick up to 1.3.47. Affected by this vulnerability is the function ExtractPostscript of the file coders/wpg.c of the component WPG File Handler. Performing a manipulation results in uncontrolled recursion. The attack may be initiated remotely. The patch is named 627b5b1b2fc2. It is suggested to install a patch to address this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Impact
The vulnerability can lead to denial of service by exhausting system resources, impacting availability of image processing services. It does not directly compromise confidentiality or integrity, but the denial of service can disrupt operations for users and administrators.
Remediation
Update to GraphicsMagick 1.3.48 or later, which contains the fix. If an upgrade is not immediately possible, restrict access to the WPG file handler or disable processing of WPG files from untrusted sources. Monitor system logs for stack overflows or repeated recursion errors.
Risk context
The medium severity and lack of EPSS data suggest a moderate risk; however, the vulnerability can be triggered remotely and may cause service disruption, so timely patching is recommended.
Affected products
- GraphicsMagick 1.3.47
- GraphicsMagick <1.3.47
Scores
- Severity
- medium
- CVSS v2
- 5
- CVSS v3
- 4.3
- CVSS v4
- 5.3
- EPSS
- —