PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107208 ImageMagick CVE debrief

ImageMagick vulnerability CVE-2026-107208 allows denial of service via crafted XMP profiles. Affected versions are ImageMagick < 6.9.13-55 and 7.0.0 <= ImageMagick < 7.1.2-30. This issue is fixed in versions 7.1.2-30 and 6.9.13-55. The vulnerability can lead to a denial-of-service condition when a crafted XMP profile is processed, causing the image-processing process to terminate. Defenders should assess and remediate this vulnerability to prevent potential denial-of-service attacks. The CVE record and source item provide details on the vulnerability, affected versions, and fixed versions.

Vendor
ImageMagick
Product
Unknown
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for ImageMagick installations should assess and remediate this vulnerability to prevent potential denial-of-service attacks. This includes verifying ImageMagick versions and applying updates if necessary. Additionally, defenders should review compensating controls for exposed systems while remediation is scheduled and verified, and check relevant monitoring, detection, and logs for exposed assets that need extra review. Affected Image

Why it matters

CVE-2026-107208 is a medium-severity vulnerability in ImageMagick that can lead to denial-of-service attacks. Defenders should assess and remediate this vulnerability to prevent potential attacks.

  • Potential denial-of-service attacks against ImageMagick installations
  • Need to verify ImageMagick versions and apply updates if necessary
  • Possible impact on image-processing services and dependent applications

Technical summary

CVE-2026-107208 is a denial-of-service vulnerability in ImageMagick, which can be triggered by a crafted XMP profile. The vulnerability affects ImageMagick versions < 6.9.13-55 and 7.0.0 <= ImageMagick < 7.1.2-30. The issue is fixed in versions 7.1.2-30 and 6.9.13-55. The vulnerability can cause the image-processing process to terminate, leading to a denial-of-service condition. Defenders should prioritize assessment and remediation of ImageMagick installations to prevent potential denial-of-service attacks. Verify ImageMagick versions and apply updates if necessary.

Defensive priority

Defenders should prioritize assessment and remediation of ImageMagick installations to prevent potential denial-of-service attacks. Verify ImageMagick versions and apply updates if necessary.

Recommended defensive actions

  • Assess ImageMagick installations for vulnerability to CVE-2026-107208
  • Verify ImageMagick versions and apply updates if necessary
  • Monitor ImageMagick installations for potential denial-of-service attacks
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source item provide details on the vulnerability, affected versions, and fixed versions. However, there is limited information on potential exploitation or victim impact. Defenders should verify ImageMagick versions and apply updates if necessary. The vulnerability is triggered by a crafted XMP profile, and the issue is fixed in versions 7.1.2-30 and 6.9.13-55. There is no information on known or confirmed attacks, but defenders should be cautious of potential denial-of-service attacks.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107208 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107208

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107208 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107208

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • ImageMagick: Denial of service with crafted XMP profile

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107208.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-27m9-54jx-fgvq

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/ImageMagick/ImageMagick/commit/907b74817836b4f88e7453f0e95c849a1c5311aa

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/ImageMagick/ImageMagick6/commit/6ba345f88a14fcce35c723c231914ae054c4281a

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-30

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-55

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.