Denial of Service in ImageMagick Affects Multiple Versions
CVE-2026-86420
6.3MEDIUM
What is CVE-2026-86420?
ImageMagick versions prior to 7.1.2-30 and 6.9.13-55 exhibit a vulnerability whereby improper management of memory allocation can lead to a denial of service. Specifically, when an operation within OpenPixelCache fails, the system does not adequately lower the memory budget, allowing repeated failure triggers to ultimately exhaust the available memory. This vulnerability can be exploited to disrupt services dependent on ImageMagick, potentially leading to application crashes and unavailability.
Affected Version(s)
ImageMagick 0 < 7.1.2-30
ImageMagick 0 < 6.9.13-55
ImageMagick 7.1.2-30