Denial of Service Vulnerability in ImageMagick by ImageMagick
CVE-2026-105825

6.9MEDIUM

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-105825?

A denial of service vulnerability exists in ImageMagick before version 6.9.13-55 and in 7.x versions prior to 7.1.2-30 due to improper handling of crafted XMP profiles. When malicious images with specially designed XMP profiles are processed, this vulnerability can cause the software to terminate unexpectedly instead of properly raising an exception, allowing attackers to disrupt operations by crashing the applications reliant on ImageMagick.

Affected Version(s)

ImageMagick 0 < 7.1.2-30

ImageMagick 0 < 6.9.13-55

ImageMagick 7.1.2-30

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yanhaoxi
.