PatchSiren cyber security CVE debrief
CVE-2026-107208 ImageMagick CVE debrief
ImageMagick vulnerability CVE-2026-107208 allows denial of service via crafted XMP profiles. Affected versions are ImageMagick < 6.9.13-55 and 7.0.0 <= ImageMagick < 7.1.2-30. This issue is fixed in versions 7.1.2-30 and 6.9.13-55. The vulnerability can lead to a denial-of-service condition when a crafted XMP profile is processed, causing the image-processing process to terminate. Defenders should assess and remediate this vulnerability to prevent potential denial-of-service attacks. The CVE record and source item provide details on the vulnerability, affected versions, and fixed versions.
- Vendor
- ImageMagick
- Product
- Unknown
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for ImageMagick installations should assess and remediate this vulnerability to prevent potential denial-of-service attacks. This includes verifying ImageMagick versions and applying updates if necessary. Additionally, defenders should review compensating controls for exposed systems while remediation is scheduled and verified, and check relevant monitoring, detection, and logs for exposed assets that need extra review. Affected Image
Why it matters
CVE-2026-107208 is a medium-severity vulnerability in ImageMagick that can lead to denial-of-service attacks. Defenders should assess and remediate this vulnerability to prevent potential attacks.
- Potential denial-of-service attacks against ImageMagick installations
- Need to verify ImageMagick versions and apply updates if necessary
- Possible impact on image-processing services and dependent applications
Technical summary
CVE-2026-107208 is a denial-of-service vulnerability in ImageMagick, which can be triggered by a crafted XMP profile. The vulnerability affects ImageMagick versions < 6.9.13-55 and 7.0.0 <= ImageMagick < 7.1.2-30. The issue is fixed in versions 7.1.2-30 and 6.9.13-55. The vulnerability can cause the image-processing process to terminate, leading to a denial-of-service condition. Defenders should prioritize assessment and remediation of ImageMagick installations to prevent potential denial-of-service attacks. Verify ImageMagick versions and apply updates if necessary.
Defensive priority
Defenders should prioritize assessment and remediation of ImageMagick installations to prevent potential denial-of-service attacks. Verify ImageMagick versions and apply updates if necessary.
Recommended defensive actions
- Assess ImageMagick installations for vulnerability to CVE-2026-107208
- Verify ImageMagick versions and apply updates if necessary
- Monitor ImageMagick installations for potential denial-of-service attacks
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details on the vulnerability, affected versions, and fixed versions. However, there is limited information on potential exploitation or victim impact. Defenders should verify ImageMagick versions and apply updates if necessary. The vulnerability is triggered by a crafted XMP profile, and the issue is fixed in versions 7.1.2-30 and 6.9.13-55. There is no information on known or confirmed attacks, but defenders should be cautious of potential denial-of-service attacks.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107208 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107208
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107208 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107208
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
ImageMagick: Denial of service with crafted XMP profile
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107208.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-27m9-54jx-fgvq
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/ImageMagick/ImageMagick/commit/907b74817836b4f88e7453f0e95c849a1c5311aa
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/ImageMagick/ImageMagick6/commit/6ba345f88a14fcce35c723c231914ae054c4281a
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-30
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-55
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.