Bilateral Blur Buffer Vulnerability in ImageMagick by ImageMagick
CVE-2026-22770
6.5MEDIUM
What is CVE-2026-22770?
ImageMagick, a widely used open-source software for image processing, contains a vulnerability related to the BilateralBlurImage method. In versions before 7.1.2-13, the last element of a set of double buffers allocated during the AcquireBilateralTLS process is not properly initialized. This flaw can lead to the release of an invalid pointer in the DestroyBilateralTLS function when memory allocation fails, potentially allowing attackers to exploit this condition and disrupt normal operations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ImageMagick < 7.1.2-13
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved