PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-106578 ImageMagick CVE debrief

ImageMagick versions prior to 7.1.2-31 and 6.9.13-56 are vulnerable to an invalid memory free in the MVG decoder, which can cause a process crash. This issue is addressed in versions 7.1.2-31 and 6.9.13-56. The vulnerability is triggered by crafted images and can lead to potential crashes. Defenders should assess exposure and prioritize patching or upgrading to fixed versions. The issue has a CVSS score of 5.9 and is classified as MEDIUM severity. ImageMagick is free and open-source software used for editing and manipulating digital images.

Vendor
ImageMagick
Product
Unknown
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-10
Advisory published
2026-10-07
Advisory updated
2026-10-10

Who should care

Defenders responsible for ImageMagick installations, particularly those using versions prior to 7.1.2-31 and 6.9.13-56, should assess exposure and prioritize patching or upgrading to fixed versions.

Why it matters

Defenders should prioritize patching or upgrading to fixed versions of ImageMagick to prevent potential crashes caused by crafted images. This requires assessing exposure, verifying inventory, and implementing compensating controls.

  • Potential crashes caused by crafted images
  • Need to verify inventory of ImageMagick installations and review for potential vulnerabilities
  • Requirement to implement compensating controls, such as monitoring and exception tracking, for ImageMagick installations

Technical summary

ImageMagick is vulnerable to an invalid memory free in the MVG decoder, which can cause a process crash. This issue is addressed in versions 7.1.2-31 and 6.9.13-56. The vulnerability is triggered by crafted images and has a CVSS score of 5.9. Defenders should prioritize patching or upgrading to fixed versions to prevent potential crashes caused by crafted images. The issue is classified as MEDIUM severity and affects ImageMagick versions prior to 7.1.2-31 and 6.9.13-56. ImageMagick is free and open-source software used for editing and manipulating digital images.

Defensive priority

Defenders should prioritize patching or upgrading to fixed versions of ImageMagick, specifically 7.1.2-31 or 6.9.13-56, to prevent potential crashes caused by crafted images.

Recommended defensive actions

  • Assess exposure and prioritize patching or upgrading to fixed versions of ImageMagick
  • Verify inventory of ImageMagick installations and review for potential vulnerabilities
  • Implement compensating controls, such as monitoring and exception tracking, for ImageMagick installations
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE Program record and NVD vulnerability detail provide information on the vulnerability. ImageMagick's official advisory and commit history also provide context. The vulnerability is confirmed in ImageMagick versions prior to 7.1.2-31 and 6.9.13-56. The issue is fixed in versions 7.1.2-31 and 6.9.13-56. Defenders should verify inventory and implement compensating controls.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-106578 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-106578

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-106578 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106578

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • ImageMagick: Invalid Memory Free in MVG decoder

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/106xxx/CVE-2026-106578.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6xf5-c3jx-rp39

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/ImageMagick/ImageMagick/commit/5d29c094020612dc8fb471b10fc1d1cc6e9e4378

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/ImageMagick/ImageMagick6/commit/bfe0117fd9742b3970383e000978d64e5e04372d

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.