PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105399 ImageMagick CVE debrief

ImageMagick before 7.1.2-31 contains a denial of service vulnerability in the MVG decoder. This CVE record was published on 2026-10-08T14:10:23.495Z and has not been modified since then. The NVD entry is currently 6.9 Medium. Defenders should assess exposure, particularly those managing ImageMagick installations. The vulnerability allows attackers to supply a crafted MVG image that triggers a long-running decoding operation, consuming excessive CPU resources and stalling image processing. Remediation priority follows from verifying and applying vendor patches. Evidence is limited to official CVE and vendor-advisory sources.

Vendor
ImageMagick
Product
Unknown
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders managing ImageMagick installations, particularly those using versions before 7.1.2-31 or 6.9.13-56, should assess exposure and prioritize remediation. This includes operators responsible for maintaining ImageMagick deployments, platform administrators, vulnerability management teams, and security teams responsible for ensuring the security and integrity of image processing operations.

Why it matters

CVE-2026-105399 is a medium-severity denial of service vulnerability in ImageMagick's MVG decoder. Defenders should verify and apply patches, monitor for crafted images, and assess exposure to prevent potential CPU resource exhaustion and image processing stalls.

  • Verify and apply patches to prevent denial of service
  • Monitor image processing for excessive CPU consumption
  • Assess exposure and prioritize remediation for ImageMagick installations

Technical summary

ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 contains a denial of service vulnerability in the MVG decoder caused by a missing limit check. Attackers can supply a crafted MVG image that triggers a long-running decoding operation, consuming excessive CPU resources and stalling image processing. This vulnerability allows for potential CPU resource exhaustion and image processing stalls if left unremediated. The vulnerability is particularly concerning for defenders managing ImageMagick installations, as it can be exploited to cause significant disruptions.

Defensive priority

Medium

Recommended defensive actions

  • Verify ImageMagick version and assess exposure
  • Apply vendor patches or updates
  • Monitor for crafted MVG images
  • Consider compensating controls for image processing
  • Review and update asset inventory for ImageMagick installations
  • Track and manage exceptions for remediation of exposed systems
  • Implement monitoring for excessive CPU consumption and image processing stalls

Evidence notes

Official CVE Program record and vendor advisory detail a denial of service vulnerability in ImageMagick before 7.1.2-31. The MVG decoder lacks a limit check, allowing crafted images to cause excessive CPU consumption.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105399 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105399

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105399 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105399

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • ImageMagick before 7.1.2-31 Denial of Service via MVG Decoder

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/105xxx/CVE-2026-105399.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qr53-hc3p-fc62

    Supplemental source - vendor-advisory

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-31-denial-of-service-via-mvg-decoder

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.