PatchSiren cyber security CVE debrief
CVE-2026-106578 ImageMagick CVE debrief
ImageMagick versions prior to 7.1.2-31 and 6.9.13-56 are vulnerable to an invalid memory free in the MVG decoder, which can cause a process crash. This issue is addressed in versions 7.1.2-31 and 6.9.13-56. The vulnerability is triggered by crafted images and can lead to potential crashes. Defenders should assess exposure and prioritize patching or upgrading to fixed versions. The issue has a CVSS score of 5.9 and is classified as MEDIUM severity. ImageMagick is free and open-source software used for editing and manipulating digital images.
- Vendor
- ImageMagick
- Product
- Unknown
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-10
Who should care
Defenders responsible for ImageMagick installations, particularly those using versions prior to 7.1.2-31 and 6.9.13-56, should assess exposure and prioritize patching or upgrading to fixed versions.
Why it matters
Defenders should prioritize patching or upgrading to fixed versions of ImageMagick to prevent potential crashes caused by crafted images. This requires assessing exposure, verifying inventory, and implementing compensating controls.
- Potential crashes caused by crafted images
- Need to verify inventory of ImageMagick installations and review for potential vulnerabilities
- Requirement to implement compensating controls, such as monitoring and exception tracking, for ImageMagick installations
Technical summary
ImageMagick is vulnerable to an invalid memory free in the MVG decoder, which can cause a process crash. This issue is addressed in versions 7.1.2-31 and 6.9.13-56. The vulnerability is triggered by crafted images and has a CVSS score of 5.9. Defenders should prioritize patching or upgrading to fixed versions to prevent potential crashes caused by crafted images. The issue is classified as MEDIUM severity and affects ImageMagick versions prior to 7.1.2-31 and 6.9.13-56. ImageMagick is free and open-source software used for editing and manipulating digital images.
Defensive priority
Defenders should prioritize patching or upgrading to fixed versions of ImageMagick, specifically 7.1.2-31 or 6.9.13-56, to prevent potential crashes caused by crafted images.
Recommended defensive actions
- Assess exposure and prioritize patching or upgrading to fixed versions of ImageMagick
- Verify inventory of ImageMagick installations and review for potential vulnerabilities
- Implement compensating controls, such as monitoring and exception tracking, for ImageMagick installations
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE Program record and NVD vulnerability detail provide information on the vulnerability. ImageMagick's official advisory and commit history also provide context. The vulnerability is confirmed in ImageMagick versions prior to 7.1.2-31 and 6.9.13-56. The issue is fixed in versions 7.1.2-31 and 6.9.13-56. Defenders should verify inventory and implement compensating controls.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-106578 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-106578
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-106578 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106578
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
ImageMagick: Invalid Memory Free in MVG decoder
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/106xxx/CVE-2026-106578.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6xf5-c3jx-rp39
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/ImageMagick/ImageMagick/commit/5d29c094020612dc8fb471b10fc1d1cc6e9e4378
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/ImageMagick/ImageMagick6/commit/bfe0117fd9742b3970383e000978d64e5e04372d
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.