Description
ImageMagick before 6.9.13-55 and 7.x before 7.1.2-30 contains a use-after-free vulnerability in the RSVG decoder when built without cairo support, triggered when a limit is hit during decoding. Attackers can supply crafted SVG files that cause a limit to be reached, leading to access of freed memory and a crash.
Published: 2026-10-08
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Denial of Service (memory corruption)
Action: Apply Patch
AI Analysis

Impact

ImageMagick versions before 6.9.13-55 and before 7.1.2-30 have a use‑after‑free flaw in the RSVG decoder when built without cairo support. When a decoding limit is reached, the decoder accesses freed memory, which can lead to a crash and potentially allow an attacker to cause memory corruption. The weakness is identified as CWE-416.

Affected Systems

The vulnerability affects ImageMagick software distributed under the ImageMagick:ImageMagick vendor/product name. All builds of ImageMagick prior to version 7.1.2-30 (and 6.9.13-55) that are compiled without cairo support are impacted. No specific patch version list is provided beyond the general upgrade to 7.1.2-30 or later.

Risk and Exploitability

The CVSS score of 8.2 indicates high severity, but the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local, as the flaw is triggered by supplying crafted SVG files during decoding. While the description only mentions a crash, use‑after‑free can potentially lead to more severe memory corruption or execution. The exploitability therefore depends on the attacker’s ability to force the application to process malicious SVG content, which is likely in untrusted input scenarios.

Generated by OpenCVE AI on October 8, 2026 at 15:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ImageMagick to version 7.1.2-30 or later, which removes the use‑after‑free bug
  • If an upgrade is not immediately possible, disable or remove RSVG decoding capabilities in the application configuration to prevent processing of SVG files
  • Monitor file inputs for crafted SVG files and enforce strict validation or sandbox processing to mitigate accidental exploitation

Generated by OpenCVE AI on October 8, 2026 at 15:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
Description ImageMagick before 6.9.13-55 and 7.x before 7.1.2-30 contains a use-after-free vulnerability in the RSVG decoder when built without cairo support, triggered when a limit is hit during decoding. Attackers can supply crafted SVG files that cause a limit to be reached, leading to access of freed memory and a crash.
Title ImageMagick before 7.1.2-30 Use-After-Free in RSVG Decoder Without Cairo
First Time appeared Imagemagick
Imagemagick imagemagick
Weaknesses CWE-416
CPEs cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
Vendors & Products Imagemagick
Imagemagick imagemagick
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Imagemagick Imagemagick
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T14:10:27.880Z

Reserved: 2026-10-05T21:59:09.590Z

Link: CVE-2026-105824

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T15:17:34.323

Modified: 2026-10-08T15:17:34.323

Link: CVE-2026-105824

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T17:00:17Z

Weaknesses