Description
ImageMagick before 7.1.2-31 contains a resource leak vulnerability that allows attackers to leave file pointers open by supplying a crafted magick script. Attackers can process malicious magick scripts to leak file descriptors, potentially exhausting resources and causing denial of service.
Published: 2026-10-08
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service via Resource Exhaustion
Action: Apply patch
AI Analysis

Impact

ImageMagick before version 7.1.2-31 can leak open file pointers when processing a specially crafted magick script, creating a resource leak that can deplete system file descriptors. This vulnerability is a classic case of CWE‑775, where an unclosed resource can be exploited to exhaust available file descriptors, ultimately disabling the application or causing a denial of service. The impact is limited to the host running ImageMagick, but any service that accepts user–supplied magick scripts could be indirectly affected.

Affected Systems

The vulnerability affects the ImageMagick software suite across all platforms where it is installed. Versions earlier than 7.1.2‑31 are susceptible. The affected product is listed as "ImageMagick:ImageMagick" in vendor terminology. No other proprietary products are listed.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate to high severity. The EPSS score is not available, so the current exploitation probability is unknown, and the vulnerability is not cited in the CISA KEV catalog. The attack vector is inferred to be local or remote file script injection; to exploit the flaw an attacker must be able to supply a crafted magick script to the ImageMagick process. If the service runs with elevated privileges or processes untrusted scripts, the resource depletion can lead to service interruption.

Generated by OpenCVE AI on October 8, 2026 at 15:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ImageMagick to version 7.1.2-31 or later
  • Validate or restrict any magick script inputs to eliminate malicious content
  • Implement system limits or monitoring to detect and prevent file descriptor exhaustion

Generated by OpenCVE AI on October 8, 2026 at 15:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
Description ImageMagick before 7.1.2-31 contains a resource leak vulnerability that allows attackers to leave file pointers open by supplying a crafted magick script. Attackers can process malicious magick scripts to leak file descriptors, potentially exhausting resources and causing denial of service.
Title ImageMagick before 7.1.2-31 Unclosed File Pointer via Magick Script
First Time appeared Imagemagick
Imagemagick imagemagick
Weaknesses CWE-775
CPEs cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
Vendors & Products Imagemagick
Imagemagick imagemagick
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Imagemagick Imagemagick
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T14:51:55.174Z

Reserved: 2026-10-05T10:56:23.833Z

Link: CVE-2026-105400

cve-icon Vulnrichment

Updated: 2026-10-08T14:51:47.622Z

cve-icon NVD

Status : Received

Published: 2026-10-08T15:17:33.127

Modified: 2026-10-08T15:17:33.127

Link: CVE-2026-105400

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T16:15:14Z

Weaknesses
  • CWE-775

    Missing Release of File Descriptor or Handle after Effective Lifetime