PatchSiren

ImageMagick CVE debriefs · Page 2

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH ImageMagick CVE published 2026-06-10

CVE-2026-49218

CVE-2026-49218 is a HIGH severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. A missing check in the DCM decoder could result in an image with invalid dimensions and that could cause crashes in other operations. This issue has been patched in versions 6.9.13-48 and 7.1.2-24.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-48994

CVE-2026-48994 is a MEDIUM severity vulnerability in ImageMagick, a free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check of a return value could lead to a heap buffer over-write in the MAT decoder on 32-bit systems. This issue has been patched in versions 6.9.13-48 and 7.1.2-24.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-48734

CVE-2026-48734 is a stack overflow vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. Prior to versions 6.9.13-49 and 7.1.2-24, a crafted MVG file could result in a stack overflow due to a missing depth or visited-set check. This issue has been patched in versions 6.9.13-49 and 7.1.2-24.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-48733

CVE-2026-48733 is a medium-severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. Prior to versions 6.9.13-49 and 7.1.2-24, an infinite loop in the subimage-search operation can happen when using a crafted image. This issue has been patched in versions 6.9.13-49 and 7.1.2-24.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-48724

CVE-2026-48724 is a MEDIUM severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. Prior to version 7.1.2-24, when using an image with mask and the Floyd-Steinberg dithering method, it causes a negative heap buffer over-write. This issue has been patched in version 7.1.2-24.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-47166

CVE-2026-47166 is a medium-severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. An attacker who can connect to a `magick -distribute-cache` service can cause a heap buffer over-read in the server process. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-47165

CVE-2026-47165 is a medium-severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, the distributed pixel cache was originally designed to operate without a challenge–response authentication model. This has been changed in versions 6.9.13-48 and 7.1.2-23. The vulnerability has a CVSS score of 4.1 and is cl [truncated]

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-46693

CVE-2026-46693 is a medium-severity vulnerability in ImageMagick, a free and open-source software used for editing and manipulating digital images. The vulnerability has a CVSS score of 4.1 and was published on [cvePublishedAt]. An attacker who can connect to a `magick -distribute-cache` service can hijack a file descriptor in the server process when a race condition is met. This issue has been patched in [truncated]

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-46692

CVE-2026-46692 is a medium-severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. An attacker who can connect to a `magick -distribute-cache` service can cause a heap buffer over-write in the server process. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-46559

CVE-2026-46559 is a medium-severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an incorrect check in the JP2 will result in an heap buffer over-write of a single byte when specifying certain options. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-46557

CVE-2026-46557 is a stack overflow vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. Prior to version 7.1.2-23, a missing depth check in the fx operation allows an attacker to pass a crafted argument, potentially leading to a stack overflow. This issue has been patched in version 7.1.2-23.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-46521

CVE-2026-46521 is a medium-severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, when using LZMA compression in the MIFF encoder, an out-of-bounds write can occur due to a missing check. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-46523

CVE-2026-46523 is a medium-severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. The vulnerability is caused by a crafted MSL image that can trigger a heap-use-after-free. This issue was fixed in versions 7.1.2.23 and 6.9.13-48.

HIGH ImageMagick CVE published 2026-06-10

CVE-2026-46522

CVE-2026-46522 is a high-severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. The vulnerability, caused by a missing check in the MIFF decoder, allows a crafted file to cause an infinite loop, resulting in CPU exhaustion. This vulnerability has a CVSS score of 7.5 and is considered HIGH severity. The affected versions of ImageMagick are prior [truncated]

HIGH ImageMagick CVE published 2026-06-10

CVE-2026-46520

CVE-2026-46520 is a HIGH severity vulnerability in ImageMagick, a free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, when reading multiple images with different dimensions, an out of bounds heap write can occur. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-45664

CVE-2026-45664 is a vulnerability in ImageMagick, a free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, a missing check in the MNG coder could allow reading more images than the list limit policy would allow, resulting in excessive resource use. This issue has been patched in versions 6.9.13-47 and 7.1.2-22.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-45624

CVE-2026-45624 is a medium-severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, when performing a polynomial distortion, an out-of-bounds over-read of 24 bytes can occur when specifying specific arguments. This issue has been patched in versions 6.9.13-47 and 7.1.2-22.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-45359

CVE-2026-45359 is a medium-severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-22, an invalid connected-components:keep-top value could result in a heap buffer over-read when performing the connected components operation. This issue has been patched in versions 6.9.13-48 and 7.1.2-22.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-45358

CVE-2026-45358 is a medium-severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, an off-by-one error in the meta encoder could result in an out-of-bounds read of a single byte. This issue has been patched in versions 6.9.13-47 and 7.1.2-22.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-45031

CVE-2026-45031 is a vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, a missing check in the PSD decoder allowed for a bypass of the list-length resource policy when decoding PSD images. Other security limits would still apply. This issue has been patched in versions 6.9.13-47 and 7.1.2-22.

MEDIUM ImageMagick CVE published 2026-06-10

CVE-2026-42326

CVE-2026-42326 is a medium-severity vulnerability in ImageMagick, a free and open-source software for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, when writing an IPTC output file, a malicious input file could cause an out-of-bounds read of a single byte. This issue has been patched in versions 6.9.13-47 and 7.1.2-22.

HIGH ImageMagick CVE published 2026-03-10

CVE-2026-28693

CVE-2026-28693 is an integer overflow vulnerability in the DIB coder of ImageMagick, a free and open-source software for editing and manipulating digital images. The vulnerability can result in out-of-bounds read or write and has been fixed in versions 7.1.2-16 and 6.9.13-41. ImageMagick is widely used for image processing, and this vulnerability could potentially be exploited to execute arbitrary code or [truncated]

HIGH ImageMagick CVE published 2026-02-24

CVE-2026-25965

CVE-2026-25965 is a high-severity vulnerability in ImageMagick, a free and open-source software used for editing and manipulating digital images. The vulnerability has a CVSS score of 8.6 and is classified as HIGH. It was published on February 24, 2026, and modified on June 30, 2026. The vulnerability allows local file disclosure (LFI) due to a path traversal issue in ImageMagick's path security policy. T [truncated]

Known exploited ImageMagick CVE published 2024-09-09

CVE-2016-3714

CVE-2016-3714 is an ImageMagick improper input validation vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. That means it should be treated as a real-world exploitation risk, not just a theoretical defect. CISA assigned a remediation due date of 2024-09-30 for the KEV entry. Defenders should inventory where ImageMagick is used, apply vendor guidance or updates, and remove or is [truncated]

Known exploited ImageMagick CVE published 2021-11-03

CVE-2016-3718

CVE-2016-3718 is an ImageMagick server-side request forgery (SSRF) vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. For defenders, the key signal is not just the vulnerability type but the KEV listing: CISA’s required action is to apply updates per vendor instructions. Any environment that processes untrusted images with ImageMagick should treat this as a high-priority remediation item.

Known exploited ImageMagick CVE published 2021-11-03

CVE-2016-3715

CVE-2016-3715 is a CISA Known Exploited Vulnerability affecting ImageMagick. The supplied corpus describes it as an arbitrary file deletion issue. Because CISA lists it in KEV, defenders should treat it as a high-priority remediation item and follow vendor update guidance.

MEDIUM Imagemagick CVE published 2017-03-06

CVE-2017-6502

CVE-2017-6502 is a denial-of-service issue in ImageMagick 6.9.7. The supplied NVD record says a specially crafted WebP file can trigger a file-descriptor leak in libmagickcore, which can exhaust resources and reduce availability. NVD classifies the weakness as CWE-119 and scores it 5.5 (Medium) with a vector that includes local access and user interaction. The CVE was published on 2017-03-06; the NVD reco [truncated]

MEDIUM Imagemagick CVE published 2017-03-06

CVE-2017-6501

CVE-2017-6501 is a denial-of-service flaw in ImageMagick 6.9.7. According to the CVE and NVD record, a specially crafted XCF file can trigger a NULL pointer dereference, with the main impact being application availability.

HIGH Imagemagick CVE published 2017-03-06

CVE-2017-6497

CVE-2017-6497 is a high-severity availability issue in ImageMagick 6.9.7. According to the CVE description and NVD data, a specially crafted PSD file can trigger a NULL pointer dereference, which can crash the application and result in denial of service. NVD classifies the issue as CVSS 3.0 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), indicating a network-reachable, low-complexity DoS risk for deployments t [truncated]

MEDIUM Imagemagick CVE published 2017-03-03

CVE-2016-10066

CVE-2016-10066 is a denial-of-service flaw in ImageMagick’s VIFF image parser. A crafted file can trigger a buffer overflow in ReadVIFFImage, causing the application to crash. The issue affects ImageMagick versions before 6.9.4-5 and is most relevant anywhere untrusted image uploads or conversions are accepted.