These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-86425 is a heap-use-after-free vulnerability in ImageMagick's PerlMagick Layer method. An attacker can trigger a denial of service by supplying a crafted list of images. This vulnerability affects ImageMagick versions before 7.1.2-30 and 6.9.x before 6.9.13-55. Defenders should assess exposure and prioritize patching to prevent potential denial of service attacks. The vulnerability has a medium s [truncated]
ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder. This allows attackers to bypass path policy write restrictions via symlink swaps. An attacker can replace a symlink between policy validation and the file write operation to write to policy-denied locations. The vulnerability affects ImageMagick installations processing untrusted inp [truncated]
CVE-2026-86423 is a heap-use-after-free vulnerability in ImageMagick's PerlMagick GetList method, which can cause a denial-of-service (crash). The vulnerability affects ImageMagick versions before 7.1.2-30 and 6.9.x before 6.9.13-55. Defenders should assess exposure and prioritize patching vulnerable systems. The CVE record and NVD entry provide details, but additional information on exploitation or affec [truncated]
ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows. This allows attackers to bypass read or write restrictions by exploiting symlink race conditions. The vulnerability affects ImageMagick installations on Windows systems, where attackers can swap symlinks between policy validation and file access to read or write policy-denied files. Defend [truncated]
CVE-2026-86421 is a memory leak vulnerability in ImageMagick's MSL image decoder. A crafted MSL image can cause memory allocation without proper deallocation, leading to a denial of service. Defenders should assess exposure, prioritize remediation, and verify affected versions. This vulnerability has a medium severity and can be triggered by a malicious MSL image, potentially causing system crashes or ins [truncated]
CVE-2026-86420 is a denial-of-service vulnerability in ImageMagick before versions 7.1.2-30 and 6.9.13-55. The vulnerability occurs when an operation inside OpenPixelCache fails, causing the memory budget to not be properly lowered. Repeated triggering of such failures can exhaust the process memory budget, leading to a denial of service. This issue can be triggered by repeated failures in OpenPixelCache [truncated]
The CVE-2026-62946 vulnerability affects ImageMagick, a free and open-source software used for editing and manipulating digital images. An integer overflow occurs when processing extremely large JNX files on 32-bit platforms, leading to a heap buffer over-write. This issue has been fixed in ImageMagick versions 6.9.13-52 and 7.1.2-27. The vulnerability has a CVSS score of 5.1, indicating a Medium severity [truncated]
A low-severity vulnerability was found in ImageMagick before version 7.1.2-26, which can cause a memory leak when handling malformed JNG files. The vulnerability has a CVSS score of 2.1 and is classified as CWE-401. The vulnerability affects the JNG encoder and can be triggered by providing malformed JNG files that fail blob operations, causing resource exhaustion. Users of ImageMagick before version 7.1. [truncated]
A low-severity vulnerability was found in ImageMagick, a software suite for creating, editing, composing, or converting bitmap images. The issue is a memory leak in the TIFF encoder that occurs when a temporary file cannot be created. This vulnerability has a CVSS score of 2.1, indicating a low severity. Users of affected ImageMagick versions should be aware of this vulnerability and take necessary precautions.
CVE-2026-61859 is a policy bypass vulnerability in the -script operation of ImageMagick before versions 7.1.2-26 and 6.9.13-51. The vulnerability allows reading files from paths that are otherwise disallowed by the configured security policy. This vulnerability could potentially allow attackers to read sensitive files that are disallowed by the security policy. Users of ImageMagick versions before 7.1.2-2 [truncated]
A memory leak vulnerability was found in ImageMagick before version 7.1.2-26. The vulnerability is located in the VIFF encoder and can be triggered by processing specially crafted VIFF images, leading to denial of service. This issue arises when memory allocation fails, allowing attackers to exhaust available memory. The vulnerability has a CVSS score of 2.1, indicating a low severity. However, users of I [truncated]
CVE-2026-61858 is a policy bypass vulnerability in ImageMagick's APNG encoder and external delegates. The vulnerability is due to missing validation checks, allowing attackers to write files to disallowed paths by bypassing configured policy restrictions through the APNG encoding process. This could potentially be used to write files to sensitive areas of the system. Users of ImageMagick versions before 7 [truncated]
CVE-2026-61857 is a heap use-after-free vulnerability in ImageMagick before 7.1.2-26. The vulnerability is caused by a missing null check when parsing XMP profiles. Attackers can craft malicious image files with specially crafted XMP data to trigger the vulnerability and cause application crashes. This vulnerability has a CVSS score of 6.3 and is classified as Medium severity. Users of affected ImageMagic [truncated]
ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed memory allocation limit in matrix-backed operations such as -canny. An attacker can supply a crafted image that causes ImageMagick to allocate more memory than permitted by the configured policy, resulting in a denial of service. This vulnerability has a CVSS score of 4.8 and a severity of MEDIUM. The vulnerability was publicly d [truncated]
CVE-2026-56372 is a heap buffer overflow vulnerability in the magnify operation of ImageMagick before version 7.1.2-19. The vulnerability allows attackers to read out of bounds memory, potentially exposing sensitive information or causing denial of service. An unrecognized magnify:method value triggers an out of bounds read. This issue affects users and administrators of ImageMagick, especially those usin [truncated]
A use-after-free vulnerability was discovered in ImageMagick's PDB decoder. The vulnerability occurs when memory allocation fails, causing a stale pointer to be used. This can be triggered by processing malicious PDB files, leading to crashes or writing a single zero byte to freed memory. The affected product is ImageMagick, specifically versions before 7.1.2-15. The vulnerability class is use-after-free, [truncated]
CVE-2026-56366 is a memory leak vulnerability in ImageMagick's META reader when processing APP1JPEG input paths. This vulnerability can be triggered by providing specially crafted APP1JPEG image files, potentially leading to denial of service through resource exhaustion. The vulnerability exists in ImageMagick before version 7.1.2-18 and has a CVSS score of 4.8, classified as MEDIUM severity. Users and ad [truncated]
CVE-2026-56374 is a heap buffer overflow vulnerability in ImageMagick's FTXT encoder. The vulnerability is due to missing boundary checks when parsing ftxt:format. Remote attackers can trigger an out of bounds read by crafting malicious FTXT image files to cause denial of service or information disclosure. This vulnerability has a CVSS score of 4.8 and a severity of MEDIUM. Users of ImageMagick versions p [truncated]
ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache updating image channel metadata before pixel cache memory allocation. Attackers can trigger memory and disk allocation failures to cause a heap-buffer-overflow read affecting any writer calling GetPixelIndex. This vulnerability has a low CVSS score of 2.1, indicating a relatively low se [truncated]
CVE-2026-55628 is a vulnerability in ImageMagick's `-concatenate` operation, which is missing policy checks. This could allow an attacker to read and write to paths disallowed by the security policy. The issue has been fixed in ImageMagick version 7.1.2-26. Affected users, especially those using versions prior to 7.1.2-26, should be aware of this vulnerability and take steps to mitigate it by updating to [truncated]
CVE-2026-56379 is a command injection vulnerability in ImageMagick's SVG decoder. Attackers can craft malicious SVG files to execute arbitrary MVG drawing commands during rendering. This vulnerability affects ImageMagick versions before 7.1.2-15 and 6.9.13-40. The vulnerability was publicly disclosed on June 23, 2026, and the details were updated on June 24, 2026. Users of affected ImageMagick versions sh [truncated]
CVE-2026-56371 is a memory leak vulnerability in ImageMagick when processing TXT files with texture attributes. The vulnerability occurs when the texture object allocated via ReadImage is not released when GetTypeMetrics fails, leaking memory each time a crafted TXT file with a texture attribute is processed. This issue affects ImageMagick versions before 7.1.2-15 and 6.9.13-40. The CVE was published on J [truncated]
CVE-2026-56378 is a medium-severity vulnerability in ImageMagick, a popular image processing library. The vulnerability is caused by a heap out-of-bounds read in the PCD coder's DecodeImage loop, which can be triggered by a crafted PCD file. This can result in a denial of service and potential disclosure of an adjacent heap byte. The vulnerability affects ImageMagick versions before 7.1.2-15 and 6.x befor [truncated]
CVE-2026-53465 is a medium-severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. Prior to version 7.1.2-25, a crafted multi-frame can result in a heap buffer over-write when encoding it with the SF3 encoder. This issue has been patched in version 7.1.2-25.
CVE-2026-53464 is a medium-severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. The vulnerability occurs when providing invalid options to the wand option parser, resulting in a small memory leak. This issue has been patched in version 7.1.2-25.
CVE-2026-53463 is a medium-severity vulnerability in ImageMagick, a free and open-source software used for editing and manipulating digital images. The vulnerability occurs when passing incorrect arguments in the distort operation, leading to a null pointer dereference. This issue has been patched in versions 6.9.13-50 and 7.1.2-25.
CVE-2026-53462 is a medium-severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, when an allocation fails in CheckPrimitiveExtent, this can result in a heap-use-after-free and lead to a crash.
CVE-2026-53461 is a HIGH severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, an incorrect loop in the ICON decoder can result in an out of bounds heap write resulting in a crash. This issue has been patched in versions 6.9.13-50 and 7.1.2-25.
CVE-2026-53460 is a HIGH severity vulnerability in ImageMagick, a free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, a missing check for maximum memory request in AcquireAlignedMemory could trigger an out-of-Memory condition. This issue has been patched in versions 6.9.13-50 and 7.1.2-25.
CVE-2026-49219 is a vulnerability in ImageMagick, a free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, an incorrect parsing of the filename can result in a policy bypass and read files disallowed by a security policy using a symlink. This issue has been patched in versions 6.9.13-48 and 7.1.2-24.