Uncontrolled Recursion Vulnerability in ImageMagick by ImageMagick
CVE-2026-105827

6.9MEDIUM

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-105827?

An uncontrolled recursion vulnerability exists in ImageMagick's CALS decoder, which can be exploited by attackers who supply specially crafted CALS images. This can lead to unbounded recursion, ultimately exhausting the application stack and crashing the process. As a result, users may experience denial of service, making it critical for administrators to update affected versions to mitigate potential exploitation.

Affected Version(s)

ImageMagick 0 < 7.1.2-30

ImageMagick 0 < 6.9.13-55

ImageMagick 7.1.2-30

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

thinhlx-vn
.