Policy Bypass Vulnerability in ImageMagick by ImageMagick Developers
CVE-2026-105823
2.1LOW
What is CVE-2026-105823?
ImageMagick versions prior to 6.9.13-56 and 7.x before 7.1.2-31 exhibit a serious flaw in the CUT encoder due to a lack of proper security policy checks. This vulnerability allows attackers to bypass the configured security policies by supplying specially crafted input to the CUT encoder. This could result in the application crashing and could potentially lead to the exposure of sensitive data. It is crucial for users to update to the recommended versions to mitigate this risk and ensure application integrity.
Affected Version(s)
ImageMagick 0 < 7.1.2-31
ImageMagick 0 < 6.9.13-56
ImageMagick 7.1.2-31