PatchSiren cyber security CVE debrief
CVE-2026-105399 ImageMagick CVE debrief
ImageMagick before 7.1.2-31 contains a denial of service vulnerability in the MVG decoder. This CVE record was published on 2026-10-08T14:10:23.495Z and has not been modified since then. The NVD entry is currently 6.9 Medium. Defenders should assess exposure, particularly those managing ImageMagick installations. The vulnerability allows attackers to supply a crafted MVG image that triggers a long-running decoding operation, consuming excessive CPU resources and stalling image processing. Remediation priority follows from verifying and applying vendor patches. Evidence is limited to official CVE and vendor-advisory sources.
- Vendor
- ImageMagick
- Product
- Unknown
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders managing ImageMagick installations, particularly those using versions before 7.1.2-31 or 6.9.13-56, should assess exposure and prioritize remediation. This includes operators responsible for maintaining ImageMagick deployments, platform administrators, vulnerability management teams, and security teams responsible for ensuring the security and integrity of image processing operations.
Why it matters
CVE-2026-105399 is a medium-severity denial of service vulnerability in ImageMagick's MVG decoder. Defenders should verify and apply patches, monitor for crafted images, and assess exposure to prevent potential CPU resource exhaustion and image processing stalls.
- Verify and apply patches to prevent denial of service
- Monitor image processing for excessive CPU consumption
- Assess exposure and prioritize remediation for ImageMagick installations
Technical summary
ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 contains a denial of service vulnerability in the MVG decoder caused by a missing limit check. Attackers can supply a crafted MVG image that triggers a long-running decoding operation, consuming excessive CPU resources and stalling image processing. This vulnerability allows for potential CPU resource exhaustion and image processing stalls if left unremediated. The vulnerability is particularly concerning for defenders managing ImageMagick installations, as it can be exploited to cause significant disruptions.
Defensive priority
Medium
Recommended defensive actions
- Verify ImageMagick version and assess exposure
- Apply vendor patches or updates
- Monitor for crafted MVG images
- Consider compensating controls for image processing
- Review and update asset inventory for ImageMagick installations
- Track and manage exceptions for remediation of exposed systems
- Implement monitoring for excessive CPU consumption and image processing stalls
Evidence notes
Official CVE Program record and vendor advisory detail a denial of service vulnerability in ImageMagick before 7.1.2-31. The MVG decoder lacks a limit check, allowing crafted images to cause excessive CPU consumption.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105399 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105399
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105399 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105399
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
ImageMagick before 7.1.2-31 Denial of Service via MVG Decoder
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/105xxx/CVE-2026-105399.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qr53-hc3p-fc62
Supplemental source - vendor-advisory
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-31-denial-of-service-via-mvg-decoder
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.