Description
ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for ticks per second in the image being encoded causes a divide-by-zero and crashes the encoder, resulting in a denial of service. The issue is fixed in 7.1.2-31 and 6.9.13-56.
Published: 2026-09-18
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

ImageMagick versions prior to 7.1.2-31 and 6.9.13-56 contain a flaw in the FLIF encoder that performs a division by zero when processing an image with an incorrect ticks‑per‑second value. The division by zero causes the encoder to crash, resulting in a denial of service. The weakness is a classic arithmetic error, classified as CWE-369.

Affected Systems

The vulnerability affects all ImageMagick products; any installation of ImageMagick older than version 7.1.2-31 or 6.9.13-56 is impacted. Users of these releases should verify the installed version and plan an upgrade.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity. The EPSS score is 0.00285, indicating a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known current exploitation. The likely attack vector is local or remote input of a malicious image to the FLIF encoder, causing the encoder to crash and denying service to the application or system using ImageMagick.

Generated by OpenCVE AI on September 19, 2026 at 19:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to ImageMagick 7.1.2-31 or 6.9.13-56, which contain the fix.
  • If an upgrade cannot be performed immediately, restrict the use of the FLIF encoder to trusted users or disable the feature entirely to prevent crashes.
  • Configure the ImageMagick policy file to block FLIF image processing from untrusted sources, preventing the vulnerable encoder from being invoked with malicious data.

Generated by OpenCVE AI on September 19, 2026 at 19:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for ticks per second in the image being encoded causes a divide-by-zero and crashes the encoder, resulting in a denial of service. The issue is fixed in 7.1.2-31 and 6.9.13-56.
Title ImageMagick before 7.1.2-31 Division by Zero in FLIF encoder
First Time appeared Imagemagick
Imagemagick imagemagick
Weaknesses CWE-369
CPEs cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
Vendors & Products Imagemagick
Imagemagick imagemagick
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Imagemagick Imagemagick
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T14:39:36.743Z

Reserved: 2026-09-18T10:59:45.138Z

Link: CVE-2026-93589

cve-icon Vulnrichment

Updated: 2026-09-18T14:39:31.463Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T14:19:09.760

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-93589

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-18T13:20:03Z

Links: CVE-2026-93589 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:45:11Z

Weaknesses