Use-After-Free Vulnerability in ImageMagick by ImageMagick Developers
CVE-2026-93586

2.1LOW

Key Information:

Vendor
CVE Published:
18 September 2026

What is CVE-2026-93586?

A use-after-free vulnerability exists in the ImagesToBlob method of ImageMagick versions prior to 7.1.2-31 and 6.9.13-56, where a pointer is not properly updated. This flaw can lead to potential impacts on the availability of the affected application, including crashes during image processing tasks. The vulnerability has been addressed in the specified versions, and users are encouraged to upgrade to mitigate risks.

Affected Version(s)

ImageMagick 0 < 7.1.2-31

ImageMagick 0 < 6.9.13-56

ImageMagick 7.1.2-31

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nosiume
.