Infinite Loop Vulnerability in ImageMagick Affecting Multiple Versions
CVE-2026-106565

5.9MEDIUM

Key Information:

Vendor
CVE Published:
7 October 2026

What is CVE-2026-106565?

ImageMagick is a widely used open-source tool for image manipulation. A security flaw prior to versions 7.1.2-32 and 6.9.13-57 arises from a missing end-of-file check while handling bzip2-compressed images. This oversight can lead to an infinite loop, potentially causing resource exhaustion that disrupts normal operations. Users are advised to upgrade to the latest versions to mitigate this issue.

Affected Version(s)

ImageMagick < 6.9.13-57 < 6.9.13-57

ImageMagick >= 7.0.0, < 7.1.2-32 < 7.0.0, 7.1.2-32

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.