Use-After-Free Vulnerability in ImageMagick's RSVG Decoder
CVE-2026-105824

8.2HIGH

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-105824?

A use-after-free vulnerability exists in the RSVG decoder of ImageMagick versions prior to 6.9.13-55 and 7.x before 7.1.2-30 when built without cairo support. This vulnerability can be exploited by attackers through specially crafted SVG files that hit a processing limit, leading to access of freed memory and resulting in application crashes. It is crucial for users to update their ImageMagick installations to mitigate the risk associated with this vulnerability.

Affected Version(s)

ImageMagick 0 < 7.1.2-30

ImageMagick 0 < 6.9.13-55

ImageMagick 7.1.2-30

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yanhaoxi
.