CVE-2026-33908 | ImageMagick up to 6.9.13-43/7.1.2-18 DestroyXMLTree recursion (GHSA-fwvm-ggf6-2p4x)
A vulnerability, which was classified as problematic, has been found in ImageMagick up to 6.9.13-43/7.1.2-18. This vulnerability affects the function DestroyXMLTree. The manipulation leads to uncontrolled recursion.
This vulnerability is traded as CVE-2026-33908. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.