PatchSiren

ImageMagick CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM ImageMagick CVE published 2026-07-30

CVE-2026-62946

The CVE-2026-62946 vulnerability affects ImageMagick, a free and open-source software used for editing and manipulating digital images. An integer overflow occurs when processing extremely large JNX files on 32-bit platforms, leading to a heap buffer over-write. This issue has been fixed in ImageMagick versions 6.9.13-52 and 7.1.2-27. The vulnerability has a CVSS score of 5.1, indicating a Medium severity [truncated]

LOW ImageMagick CVE published 2026-07-15

CVE-2026-61866

A low-severity vulnerability was found in ImageMagick before version 7.1.2-26, which can cause a memory leak when handling malformed JNG files. The vulnerability has a CVSS score of 2.1 and is classified as CWE-401. The vulnerability affects the JNG encoder and can be triggered by providing malformed JNG files that fail blob operations, causing resource exhaustion. Users of ImageMagick before version 7.1. [truncated]

LOW ImageMagick CVE published 2026-07-15

CVE-2026-61863

A low-severity vulnerability was found in ImageMagick, a software suite for creating, editing, composing, or converting bitmap images. The issue is a memory leak in the TIFF encoder that occurs when a temporary file cannot be created. This vulnerability has a CVSS score of 2.1, indicating a low severity. Users of affected ImageMagick versions should be aware of this vulnerability and take necessary precautions.

MEDIUM ImageMagick CVE published 2026-07-15

CVE-2026-61859

CVE-2026-61859 is a policy bypass vulnerability in the -script operation of ImageMagick before versions 7.1.2-26 and 6.9.13-51. The vulnerability allows reading files from paths that are otherwise disallowed by the configured security policy. This vulnerability could potentially allow attackers to read sensitive files that are disallowed by the security policy. Users of ImageMagick versions before 7.1.2-2 [truncated]

LOW ImageMagick CVE published 2026-07-11

CVE-2026-61870

A memory leak vulnerability was found in ImageMagick before version 7.1.2-26. The vulnerability is located in the VIFF encoder and can be triggered by processing specially crafted VIFF images, leading to denial of service. This issue arises when memory allocation fails, allowing attackers to exhaust available memory. The vulnerability has a CVSS score of 2.1, indicating a low severity. However, users of I [truncated]

MEDIUM ImageMagick CVE published 2026-07-11

CVE-2026-61858

CVE-2026-61858 is a policy bypass vulnerability in ImageMagick's APNG encoder and external delegates. The vulnerability is due to missing validation checks, allowing attackers to write files to disallowed paths by bypassing configured policy restrictions through the APNG encoding process. This could potentially be used to write files to sensitive areas of the system. Users of ImageMagick versions before 7 [truncated]

MEDIUM ImageMagick CVE published 2026-07-11

CVE-2026-61857

CVE-2026-61857 is a heap use-after-free vulnerability in ImageMagick before 7.1.2-26. The vulnerability is caused by a missing null check when parsing XMP profiles. Attackers can craft malicious image files with specially crafted XMP data to trigger the vulnerability and cause application crashes. This vulnerability has a CVSS score of 6.3 and is classified as Medium severity. Users of affected ImageMagic [truncated]

MEDIUM ImageMagick CVE published 2026-07-11

CVE-2026-61465

ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed memory allocation limit in matrix-backed operations such as -canny. An attacker can supply a crafted image that causes ImageMagick to allocate more memory than permitted by the configured policy, resulting in a denial of service. This vulnerability has a CVSS score of 4.8 and a severity of MEDIUM. The vulnerability was publicly d [truncated]

MEDIUM ImageMagick CVE published 2026-07-11

CVE-2026-56372

CVE-2026-56372 is a heap buffer overflow vulnerability in the magnify operation of ImageMagick before version 7.1.2-19. The vulnerability allows attackers to read out of bounds memory, potentially exposing sensitive information or causing denial of service. An unrecognized magnify:method value triggers an out of bounds read. This issue affects users and administrators of ImageMagick, especially those usin [truncated]

MEDIUM ImageMagick CVE published 2026-07-10

CVE-2026-56373

A use-after-free vulnerability was discovered in ImageMagick's PDB decoder. The vulnerability occurs when memory allocation fails, causing a stale pointer to be used. This can be triggered by processing malicious PDB files, leading to crashes or writing a single zero byte to freed memory. The affected product is ImageMagick, specifically versions before 7.1.2-15. The vulnerability class is use-after-free, [truncated]

MEDIUM ImageMagick CVE published 2026-07-10

CVE-2026-56366

CVE-2026-56366 is a memory leak vulnerability in ImageMagick's META reader when processing APP1JPEG input paths. This vulnerability can be triggered by providing specially crafted APP1JPEG image files, potentially leading to denial of service through resource exhaustion. The vulnerability exists in ImageMagick before version 7.1.2-18 and has a CVSS score of 4.8, classified as MEDIUM severity. Users and ad [truncated]

MEDIUM ImageMagick CVE published 2026-07-08

CVE-2026-56374

CVE-2026-56374 is a heap buffer overflow vulnerability in ImageMagick's FTXT encoder. The vulnerability is due to missing boundary checks when parsing ftxt:format. Remote attackers can trigger an out of bounds read by crafting malicious FTXT image files to cause denial of service or information disclosure. This vulnerability has a CVSS score of 4.8 and a severity of MEDIUM. Users of ImageMagick versions p [truncated]

LOW ImageMagick CVE published 2026-07-08

CVE-2026-56362

ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache updating image channel metadata before pixel cache memory allocation. Attackers can trigger memory and disk allocation failures to cause a heap-buffer-overflow read affecting any writer calling GetPixelIndex. This vulnerability has a low CVSS score of 2.1, indicating a relatively low se [truncated]

MEDIUM ImageMagick CVE published 2026-07-01

CVE-2026-55628

CVE-2026-55628 is a vulnerability in ImageMagick's `-concatenate` operation, which is missing policy checks. This could allow an attacker to read and write to paths disallowed by the security policy. The issue has been fixed in ImageMagick version 7.1.2-26. Affected users, especially those using versions prior to 7.1.2-26, should be aware of this vulnerability and take steps to mitigate it by updating to [truncated]

CRITICAL ImageMagick CVE published 2026-06-23

CVE-2026-56379

CVE-2026-56379 is a command injection vulnerability in ImageMagick's SVG decoder. Attackers can craft malicious SVG files to execute arbitrary MVG drawing commands during rendering. This vulnerability affects ImageMagick versions before 7.1.2-15 and 6.9.13-40. The vulnerability was publicly disclosed on June 23, 2026, and the details were updated on June 24, 2026. Users of affected ImageMagick versions sh [truncated]

MEDIUM ImageMagick CVE published 2026-06-23

CVE-2026-56371

CVE-2026-56371 is a memory leak vulnerability in ImageMagick when processing TXT files with texture attributes. The vulnerability occurs when the texture object allocated via ReadImage is not released when GetTypeMetrics fails, leaking memory each time a crafted TXT file with a texture attribute is processed. This issue affects ImageMagick versions before 7.1.2-15 and 6.9.13-40. The CVE was published on J [truncated]

MEDIUM ImageMagick CVE published 2026-06-21

CVE-2026-56378

CVE-2026-56378 is a medium-severity vulnerability in ImageMagick, a popular image processing library. The vulnerability is caused by a heap out-of-bounds read in the PCD coder's DecodeImage loop, which can be triggered by a crafted PCD file. This can result in a denial of service and potential disclosure of an adjacent heap byte. The vulnerability affects ImageMagick versions before 7.1.2-15 and 6.x befor [truncated]

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-53465

CVE-2026-53465 is a medium-severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. Prior to version 7.1.2-25, a crafted multi-frame can result in a heap buffer over-write when encoding it with the SF3 encoder. This issue has been patched in version 7.1.2-25.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-53464

CVE-2026-53464 is a medium-severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. The vulnerability occurs when providing invalid options to the wand option parser, resulting in a small memory leak. This issue has been patched in version 7.1.2-25.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-53463

CVE-2026-53463 is a medium-severity vulnerability in ImageMagick, a free and open-source software used for editing and manipulating digital images. The vulnerability occurs when passing incorrect arguments in the distort operation, leading to a null pointer dereference. This issue has been patched in versions 6.9.13-50 and 7.1.2-25.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-53462

CVE-2026-53462 is a medium-severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, when an allocation fails in CheckPrimitiveExtent, this can result in a heap-use-after-free and lead to a crash.

HIGH ImageMagick CVE published 2026-06-10

CVE-2026-53461

CVE-2026-53461 is a HIGH severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, an incorrect loop in the ICON decoder can result in an out of bounds heap write resulting in a crash. This issue has been patched in versions 6.9.13-50 and 7.1.2-25.

HIGH ImageMagick CVE published 2026-06-10

CVE-2026-53460

CVE-2026-53460 is a HIGH severity vulnerability in ImageMagick, a free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, a missing check for maximum memory request in AcquireAlignedMemory could trigger an out-of-Memory condition. This issue has been patched in versions 6.9.13-50 and 7.1.2-25.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-49219

CVE-2026-49219 is a vulnerability in ImageMagick, a free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, an incorrect parsing of the filename can result in a policy bypass and read files disallowed by a security policy using a symlink. This issue has been patched in versions 6.9.13-48 and 7.1.2-24.

HIGH ImageMagick CVE published 2026-06-10

CVE-2026-49218

CVE-2026-49218 is a HIGH severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. A missing check in the DCM decoder could result in an image with invalid dimensions and that could cause crashes in other operations. This issue has been patched in versions 6.9.13-48 and 7.1.2-24.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-48994

CVE-2026-48994 is a MEDIUM severity vulnerability in ImageMagick, a free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check of a return value could lead to a heap buffer over-write in the MAT decoder on 32-bit systems. This issue has been patched in versions 6.9.13-48 and 7.1.2-24.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-48734

CVE-2026-48734 is a stack overflow vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. Prior to versions 6.9.13-49 and 7.1.2-24, a crafted MVG file could result in a stack overflow due to a missing depth or visited-set check. This issue has been patched in versions 6.9.13-49 and 7.1.2-24.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-48733

CVE-2026-48733 is a medium-severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. Prior to versions 6.9.13-49 and 7.1.2-24, an infinite loop in the subimage-search operation can happen when using a crafted image. This issue has been patched in versions 6.9.13-49 and 7.1.2-24.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-48724

CVE-2026-48724 is a MEDIUM severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. Prior to version 7.1.2-24, when using an image with mask and the Floyd-Steinberg dithering method, it causes a negative heap buffer over-write. This issue has been patched in version 7.1.2-24.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-47166

CVE-2026-47166 is a medium-severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. An attacker who can connect to a `magick -distribute-cache` service can cause a heap buffer over-read in the server process. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-47165

CVE-2026-47165 is a medium-severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, the distributed pixel cache was originally designed to operate without a challenge–response authentication model. This has been changed in versions 6.9.13-48 and 7.1.2-23. The vulnerability has a CVSS score of 4.1 and is cl [truncated]

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-46693

CVE-2026-46693 is a medium-severity vulnerability in ImageMagick, a free and open-source software used for editing and manipulating digital images. The vulnerability has a CVSS score of 4.1 and was published on [cvePublishedAt]. An attacker who can connect to a `magick -distribute-cache` service can hijack a file descriptor in the server process when a race condition is met. This issue has been patched in [truncated]

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-46692

CVE-2026-46692 is a medium-severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. An attacker who can connect to a `magick -distribute-cache` service can cause a heap buffer over-write in the server process. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-46559

CVE-2026-46559 is a medium-severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an incorrect check in the JP2 will result in an heap buffer over-write of a single byte when specifying certain options. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-46557

CVE-2026-46557 is a stack overflow vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. Prior to version 7.1.2-23, a missing depth check in the fx operation allows an attacker to pass a crafted argument, potentially leading to a stack overflow. This issue has been patched in version 7.1.2-23.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-46521

CVE-2026-46521 is a medium-severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, when using LZMA compression in the MIFF encoder, an out-of-bounds write can occur due to a missing check. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-46523

CVE-2026-46523 is a medium-severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. The vulnerability is caused by a crafted MSL image that can trigger a heap-use-after-free. This issue was fixed in versions 7.1.2.23 and 6.9.13-48.

HIGH ImageMagick CVE published 2026-06-10

CVE-2026-46522

CVE-2026-46522 is a high-severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. The vulnerability, caused by a missing check in the MIFF decoder, allows a crafted file to cause an infinite loop, resulting in CPU exhaustion. This vulnerability has a CVSS score of 7.5 and is considered HIGH severity. The affected versions of ImageMagick are prior [truncated]

HIGH ImageMagick CVE published 2026-06-10

CVE-2026-46520

CVE-2026-46520 is a HIGH severity vulnerability in ImageMagick, a free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, when reading multiple images with different dimensions, an out of bounds heap write can occur. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-45664

CVE-2026-45664 is a vulnerability in ImageMagick, a free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, a missing check in the MNG coder could allow reading more images than the list limit policy would allow, resulting in excessive resource use. This issue has been patched in versions 6.9.13-47 and 7.1.2-22.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-45624

CVE-2026-45624 is a medium-severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, when performing a polynomial distortion, an out-of-bounds over-read of 24 bytes can occur when specifying specific arguments. This issue has been patched in versions 6.9.13-47 and 7.1.2-22.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-45359

CVE-2026-45359 is a medium-severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-22, an invalid connected-components:keep-top value could result in a heap buffer over-read when performing the connected components operation. This issue has been patched in versions 6.9.13-48 and 7.1.2-22.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-45358

CVE-2026-45358 is a medium-severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, an off-by-one error in the meta encoder could result in an out-of-bounds read of a single byte. This issue has been patched in versions 6.9.13-47 and 7.1.2-22.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-45031

CVE-2026-45031 is a vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, a missing check in the PSD decoder allowed for a bypass of the list-length resource policy when decoding PSD images. Other security limits would still apply. This issue has been patched in versions 6.9.13-47 and 7.1.2-22.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-42326

CVE-2026-42326 is a medium-severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, when writing an IPTC output file, a malicious input file could cause an out-of-bounds read of a single byte. This issue has been patched in versions 6.9.13-47 and 7.1.2-22.

HIGH ImageMagick CVE published 2026-03-10

CVE-2026-28693

CVE-2026-28693 is an integer overflow vulnerability in the DIB coder of ImageMagick, a free and open-source software for editing and manipulating digital images. The vulnerability can result in out-of-bounds read or write and has been fixed in versions 7.1.2-16 and 6.9.13-41. ImageMagick is widely used for image processing, and this vulnerability could potentially be exploited to execute arbitrary code or [truncated]

HIGH ImageMagick CVE published 2026-02-24

CVE-2026-25965

CVE-2026-25965 is a high-severity vulnerability in ImageMagick, a free and open-source software used for editing and manipulating digital images. The vulnerability has a CVSS score of 8.6 and is classified as HIGH. It was published on February 24, 2026, and modified on June 30, 2026. The vulnerability allows local file disclosure (LFI) due to a path traversal issue in ImageMagick's path security policy. T [truncated]

Known exploited ImageMagick CVE published 2024-09-09

CVE-2016-3714

CVE-2016-3714 is an ImageMagick improper input validation vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. That means it should be treated as a real-world exploitation risk, not just a theoretical defect. CISA assigned a remediation due date of 2024-09-30 for the KEV entry. Defenders should inventory where ImageMagick is used, apply vendor guidance or updates, and remove or is [truncated]

Known exploited ImageMagick CVE published 2021-11-03

CVE-2016-3718

CVE-2016-3718 is an ImageMagick server-side request forgery (SSRF) vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. For defenders, the key signal is not just the vulnerability type but the KEV listing: CISA’s required action is to apply updates per vendor instructions. Any environment that processes untrusted images with ImageMagick should treat this as a high-priority remediation item.

Known exploited ImageMagick CVE published 2021-11-03

CVE-2016-3715

CVE-2016-3715 is a CISA Known Exploited Vulnerability affecting ImageMagick. The supplied corpus describes it as an arbitrary file deletion issue. Because CISA lists it in KEV, defenders should treat it as a high-priority remediation item and follow vendor update guidance.