Impact
The vulnerability arises when ImageMagick processes a crafted XMP profile that exceeds its recursion limit. The engine treats the over‑limit condition as a fatal error rather than a normal exception, causing the image‑processing process to terminate. This results in a denial of service that can affect any application dependent on ImageMagick. The weakness is reflected in CWE‑400 for uncontrolled resource consumption and CWE‑674 for uncontrolled recursion.
Affected Systems
The issue affects the ImageMagick library in all versions prior to 7.1.2‑30 and 6.9.13‑55. Any system that relies on these older releases, including web servers, content management systems or other image‑handling services that invoke ImageMagick, is vulnerable.
Risk and Exploitability
The CVSS base score of 5.3 indicates a moderate impact, while the EPSS score is not available, so the current likelihood of exploitation is uncertain. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be through the ingestion of a malicious image file containing a specially crafted XMP profile; this can be delivered locally or remotely to any service that processes user‑supplied images.
OpenCVE Enrichment