Description
ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 contains an invalid memory free vulnerability in the MVG decoder. Attackers can supply a crafted MVG image for processing to trigger the invalid free and crash the application, causing a denial of service.
Published: 2026-10-08
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

ImageMagick before 6.9.13‑56 and 7.x before 7.1.2‑31 is vulnerable to an invalid memory free in the MVG decoder. A crafted MVG image can trigger the bug, causing the application to crash. The resulting impact is a denial of service as legitimate image processing is disrupted, and the vulnerability is a CWE‑763 flaw—incorrect memory deallocation leading to a crash.

Affected Systems

The affected products are ImageMagick ImageMagick, all versions before 6.9.13‑56 and 7.x before 7.1.2‑31. These versions are widely used in web servers, content management systems, and image processing pipelines. If any component relies on MVG decoding, the vulnerability applies. Users running older ImageMagick installations should check their exact version for compliance. No specific vendor patch is listed, but references indicate the vulnerability is remediated in 7.1.2‑31 and later, and earlier 6.9.13‑56 updates.

Risk and Exploitability

The CVSS score of 8.2 marks this issue as high severity. The EPSS score is not available, so the exploitation likelihood is not quantified, and the vulnerability is not in the CISA KEV catalog. Attackers would need to supply a malicious MVG file to the ImageMagick engine, which is typically performed via user‑controlled input such as uploads or processing of external content. This can crash the service or application, leading to service disruption. The vulnerability does not grant arbitrary code execution or data exfiltration, but it can disrupt operations for customers that rely on ImageMagick for image rendering.

Generated by OpenCVE AI on October 8, 2026 at 15:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ImageMagick to version 7.1.2‑31 or later, which includes the fix for the MVG decoder invalid free.
  • Verify that any services using ImageMagick reject or sandbox untrusted MVG files, and disable MVG decoding if not required.
  • Implement monitoring of ImageMagick crashes to detect exploitation attempts early.

Generated by OpenCVE AI on October 8, 2026 at 15:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
Description ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 contains an invalid memory free vulnerability in the MVG decoder. Attackers can supply a crafted MVG image for processing to trigger the invalid free and crash the application, causing a denial of service.
Title ImageMagick before 7.1.2-31 Invalid Memory Free in MVG Decoder
First Time appeared Imagemagick
Imagemagick imagemagick
Weaknesses CWE-763
CPEs cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
Vendors & Products Imagemagick
Imagemagick imagemagick
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Imagemagick Imagemagick
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T14:50:54.558Z

Reserved: 2026-10-05T10:56:23.833Z

Link: CVE-2026-105405

cve-icon Vulnrichment

Updated: 2026-10-08T14:50:41.297Z

cve-icon NVD

Status : Received

Published: 2026-10-08T15:17:33.963

Modified: 2026-10-08T15:17:33.963

Link: CVE-2026-105405

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T17:00:17Z

Weaknesses
  • CWE-763

    Release of Invalid Pointer or Reference