Description
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57.
Published: 2026-10-07
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service via resource exhaustion
Action: Immediate Patch
AI Analysis

Impact

ImageMagick has a missing end‑of‑file check while decoding bzip2‑compressed images, which can cause an infinite loop that exhausts CPU and memory. The result is a denial of service affecting any service that processes images with ImageMagick. This weakness corresponds to CWE‑400 (Uncontrolled Resource Consumption) and CWE‑835 (Infinite Loop).

Affected Systems

Vendor ImageMagick with product ImageMagick. All releases older than 7.1.2‑32 and older than 6.9.13‑57 are vulnerable. The problem is fixed in those exact release numbers and later versions.

Risk and Exploitability

The CVSS score of 5.9 classifies the issue as moderate severity. No EPSS data is available, so the likelihood of exploitation is unknown, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the delivery of a crafted bzip2 image to any application that calls ImageMagick for image manipulation. An attacker who can supply such input can force an indefinite loop, draining system resources and disrupting service availability. No remote code execution or privilege escalation is possible.

Generated by OpenCVE AI on October 7, 2026 at 16:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade all ImageMagick installations to version 7.1.2‑32 or newer, or 6.9.13‑57 or newer.
  • If an immediate upgrade is infeasible, configure ImageMagick to reject or bypass bzip2‑compressed inputs from untrusted sources, or wrap the call in a CPU‑time limiting sandbox.
  • Restart any services that use ImageMagick after applying the upgrade or configuration change, and monitor system resource metrics for signs of continued exhaustion.

Generated by OpenCVE AI on October 7, 2026 at 16:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Imagemagick
Imagemagick imagemagick
Vendors & Products Imagemagick
Imagemagick imagemagick

Wed, 07 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Description ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57.
Title ImageMagick: Infinite Loop in bzip2 compressed images.
Weaknesses CWE-400
CWE-835
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Imagemagick Imagemagick
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-07T17:10:51.659Z

Reserved: 2026-10-06T20:31:59.017Z

Link: CVE-2026-106565

cve-icon Vulnrichment

Updated: 2026-10-07T17:09:59.947Z

cve-icon NVD

Status : Received

Published: 2026-10-07T16:17:40.627

Modified: 2026-10-07T18:17:17.257

Link: CVE-2026-106565

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T16:45:08Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')