Description
ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CUBE and HALD) coder: when a specific command line option is supplied, the decoder does not check a configured resource limit, which can result in extra memory allocation. A local user able to pass command line options to ImageMagick can therefore exceed the intended memory policy limit, causing a limited availability impact. The issue is fixed in 7.1.2-31 and 6.9.13-56.
Published: 2026-09-18
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Limited Availability
Action: Apply Patch
AI Analysis

Impact

ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD decoder. When a specific command line option is supplied, the decoder skips an enforced resource limit, leading to excessive memory allocation and a limited availability impact.

Affected Systems

ImageMagick versions before 7.1.2-31 and 6.9.13-56 are affected. The vulnerability impacts the ImageMagick:ImageMagick product as identified by the CNA.

Risk and Exploitability

The CVSS score of 4.8 signals moderate severity. The EPSS score of < 1% indicates a very low exploitation probability, and the vulnerability is not listed in CISA KEV. Exploitation requires local access to ImageMagick's command line; therefore the likelihood of widespread attacks is low, but organizations allowing local command execution should patch promptly to prevent potential denial of service.

Generated by OpenCVE AI on September 23, 2026 at 14:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ImageMagick to version 7.1.2-31 or 6.9.13-56, which contain the fix for the policy bypass.
  • If an upgrade cannot be applied immediately, restrict local users from providing arbitrary command line options that trigger the PCD decoder, such as by disabling the decoder in the policy or removing its support.
  • Monitor image processing workloads for anomalous memory consumption and review logs for signs of excessive allocation that could indicate exploitation attempts.

Generated by OpenCVE AI on September 23, 2026 at 14:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
References
Metrics threat_severity

None

threat_severity

Low


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CUBE and HALD) coder: when a specific command line option is supplied, the decoder does not check a configured resource limit, which can result in extra memory allocation. A local user able to pass command line options to ImageMagick can therefore exceed the intended memory policy limit, causing a limited availability impact. The issue is fixed in 7.1.2-31 and 6.9.13-56.
Title ImageMagick before 7.1.2-31 Policy Bypass via PCD decoder
First Time appeared Imagemagick
Imagemagick imagemagick
Weaknesses CWE-400
CPEs cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
Vendors & Products Imagemagick
Imagemagick imagemagick
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Imagemagick Imagemagick
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T18:06:01.695Z

Reserved: 2026-09-18T10:59:45.138Z

Link: CVE-2026-93587

cve-icon Vulnrichment

Updated: 2026-09-18T18:05:58.612Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T14:19:09.410

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-93587

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-18T13:20:01Z

Links: CVE-2026-93587 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T14:15:06Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-770

    Allocation of Resources Without Limits or Throttling