Description
ImageMagick before 7.1.2-31 contains a denial of service vulnerability that allows attackers to disrupt processing by supplying a crafted XMP profile. Attackers can embed a malicious XMP profile that triggers a failure when determining the numerator and denominator, crashing or hanging image processing.
Published: 2026-10-08
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

ImageMagick versions before 7.1.2‑31 are vulnerable to a denial‑of‑service attack due to improper handling of XMP profiles. An attacker can embed a malicious XMP profile that causes the parser to miscalculate a numerator and denominator, leading to a crash or hang during image processing. This flaw can result in application downtime or blocked image rendering for users.

Affected Systems

ImageMagick, all releases older than 7.1.2‑31. The vulnerability applies to every instance that parses XMP metadata in images, including command‑line utilities and server‑side image processing pipelines.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity. EPSS is not available and the issue is not listed in CISA KEV, suggesting limited public exploitation data. The vulnerability can be triggered by any process that ingests a crafted image, so attackers who can provide malicious files to ImageMagick—whether locally or via a remote application—may force the program to crash or hang. Exploitation requires that ImageMagick parses untrusted XMP data; if an application disables XMP support or runs with limited privileges, the risk is mitigated. Nevertheless, because the failure leads to a denial of service, the potential impact on availability remains significant.

Generated by OpenCVE AI on October 8, 2026 at 15:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ImageMagick to version 7.1.2‑31 or later, which contains the patch for the XMP parsing flaw.
  • If immediate upgrade is not possible, disable XMP profile handling in ImageMagick configuration or remove the `-define +XMP` setting to prevent parsing of XMP data.
  • Validate and sanitize any image files before passing them to ImageMagick, ensuring that only trusted sources are processed.

Generated by OpenCVE AI on October 8, 2026 at 15:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
Description ImageMagick before 7.1.2-31 contains a denial of service vulnerability that allows attackers to disrupt processing by supplying a crafted XMP profile. Attackers can embed a malicious XMP profile that triggers a failure when determining the numerator and denominator, crashing or hanging image processing.
Title ImageMagick before 7.1.2-31 Denial of Service via XMP Profile Parsing
First Time appeared Imagemagick
Imagemagick imagemagick
Weaknesses CWE-400
CPEs cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
Vendors & Products Imagemagick
Imagemagick imagemagick
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Imagemagick Imagemagick
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T14:10:25.137Z

Reserved: 2026-10-05T10:56:23.833Z

Link: CVE-2026-105402

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T15:17:33.473

Modified: 2026-10-08T15:17:33.473

Link: CVE-2026-105402

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T15:45:11Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption