Heap Buffer Over-Read Vulnerability in ImageMagick Software
CVE-2026-25987
5.3MEDIUM
What is CVE-2026-25987?
ImageMagick, a widely used open-source software for editing and manipulating digital images, has a vulnerability in its MAP image decoder. This issue arises when processing specially crafted MAP files, which may lead to potentially disruptive behavior such as crashes or unintended memory exposure during the decoding process. Users are urged to update to versions 7.1.2-15 or 6.9.13-40 or later, which address this vulnerability.
Affected Version(s)
ImageMagick >= 7.0.0, < 7.1.2-15 < 7.0.0, 7.1.2-15
ImageMagick < 6.9.13-40 < 6.9.13-40