Security Policy Bypass in ImageMagick Affects Major Versions
CVE-2026-105826

6.9MEDIUM

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-105826?

ImageMagick versions prior to 6.9.13-55 and 7.x before 7.1.2-30 have a security policy bypass vulnerability in the MAT decoder. This flaw allows attackers to create a specially crafted MAT image that circumvents enforced temporary file size limits, potentially leading to excessive disk resource consumption as decompressed data may be written to temporary files exceeding the configured policies. Organizations should promptly review their ImageMagick installations and apply necessary updates to mitigate this vulnerability.

Affected Version(s)

ImageMagick 0 < 7.1.2-30

ImageMagick 0 < 6.9.13-55

ImageMagick 7.1.2-30

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gb1dev
.