Description
ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 contains a denial of service vulnerability in the MVG decoder caused by a missing limit check. Attackers can supply a crafted MVG image that triggers a long-running decoding operation, consuming excessive CPU resources and stalling image processing.
Published: 2026-10-08
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

ImageMagick versions earlier than 6.9.13-56 and all 7.x releases before 7.1.2-31 contain a flaw in the MVG decoder that omits a critical limit check. When a maliciously crafted MVG image is processed, the decoder enters a computation path that can run for an extended period, consuming a large amount of CPU resources and preventing the decoding operation from completing. This leads to a denial of service for any application or service that relies on ImageMagick to render or convert images.

Affected Systems

All deployments of the ImageMagick suite using a version older than 6.9.13-56 or any 7.x release earlier than 7.1.2-31 are potentially affected. The only vendor listed is ImageMagick, and the issue applies across all platforms that run these release lines.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity denial of service. The EPSS score is not available, meaning public data does not provide a probability of exploitation, while the absence from the KEV catalog does not eliminate the threat. The likely attack vector is via any process that accepts externally supplied image files—web servers, content management systems, or other services that invoke ImageMagick. Based on the description, it is inferred that an attacker can supply a malicious MVG image to such a process, triggering the runaway decoding and overwhelming the host’s CPU, which results in service interruption for legitimate users.

Generated by OpenCVE AI on October 8, 2026 at 16:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ImageMagick to 7.1.2-31 or later (or to 6.9.13-56 or later for older releases).
  • Disable support for the MVG image format if it is not required, or enforce strict size and time limits on image decoding operations.
  • Monitor system CPU usage for abnormal spikes that may indicate an ongoing malicious decoding attempt and isolate any processes that exceed established thresholds.

Generated by OpenCVE AI on October 8, 2026 at 16:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
Description ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 contains a denial of service vulnerability in the MVG decoder caused by a missing limit check. Attackers can supply a crafted MVG image that triggers a long-running decoding operation, consuming excessive CPU resources and stalling image processing.
Title ImageMagick before 7.1.2-31 Denial of Service via MVG Decoder
First Time appeared Imagemagick
Imagemagick imagemagick
Weaknesses CWE-400
CPEs cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
Vendors & Products Imagemagick
Imagemagick imagemagick
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Imagemagick Imagemagick
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T17:52:52.862Z

Reserved: 2026-10-05T10:56:23.833Z

Link: CVE-2026-105399

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T15:17:32.960

Modified: 2026-10-08T15:17:32.960

Link: CVE-2026-105399

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T16:30:05Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption