Description
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, when ImageMagick is built without Cairo support, a crafted RSVG image that reaches a resource limit can cause the RSVG decoder to free image state twice and then use freed memory, crashing the process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55.
Published: 2026-10-07
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

ImageMagick contains a use‑after‑free flaw in the RSVG decoder that occurs when the program is built without Cairo support. A crafted RSVG image that reaches a resource limit triggers the decoder to free the same memory location twice and then access it, causing the ImageMagick process to crash. Because the crash terminates the processing thread, an attacker can execute a denial‑of‑service attack against any system that parses such an image.

Affected Systems

All installations of ImageMagick prior to version 7.1.2-30 and 6.9.13-55 that are compiled without Cairo support are vulnerable. The issue has been fixed in releases 7.1.2-30 and 6.9.13-55 and later upward. Users running older builds on any platform (Linux, Windows, macOS) are affected unless they compile with Cairo enabled or otherwise disable RSVG handling.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity. No EPSS score is available, so the current exploitation probability is unknown. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog. Based on the description, it is inferred that attackers would need access to a system that accepts image uploads or otherwise processes RSVG files, and that the exploit path is local or remote via a web or file‑processing service. No evidence of remote code execution is present, so the attack primarily results in a denial‑of service rather than full system compromise.

Generated by OpenCVE AI on October 7, 2026 at 18:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to ImageMagick 7.1.2-30 or later, or 6.9.13-55 or later, which contain the patch
  • If the application cannot be upgraded immediately, re‑compile ImageMagick with Cairo support enabled so the vulnerable code path is not exercised
  • If RSVG functionality is not required, remove or disable RSVG image handling from the build to eliminate the attack surface

Generated by OpenCVE AI on October 7, 2026 at 18:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Imagemagick
Imagemagick imagemagick
Vendors & Products Imagemagick
Imagemagick imagemagick

Wed, 07 Oct 2026 16:15:00 +0000

Type Values Removed Values Added
Description ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, when ImageMagick is built without Cairo support, a crafted RSVG image that reaches a resource limit can cause the RSVG decoder to free image state twice and then use freed memory, crashing the process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55.
Title ImageMagick: Use-After-Free in RSVG decoder that is build without cairo support
Weaknesses CWE-415
CWE-416
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Imagemagick Imagemagick
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-07T17:40:58.685Z

Reserved: 2026-10-07T14:34:14.814Z

Link: CVE-2026-107209

cve-icon Vulnrichment

Updated: 2026-10-07T17:40:45.599Z

cve-icon NVD

Status : Received

Published: 2026-10-07T16:17:45.940

Modified: 2026-10-07T18:17:18.337

Link: CVE-2026-107209

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T18:30:14Z

Weaknesses