Description
ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer allocation for image pixels. Attackers can bypass resource policies by processing specially crafted UHDR images, potentially causing denial of service through excessive memory allocation.
Published: 2026-09-18
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

An ImageMagick policy bypass exists in the UHDR encoder, where pixel buffer allocation does not enforce policy checks during memory allocation. Attackers can craft special UHDR images that trigger uncontrolled memory allocation, potentially exhausting system resources and causing a denial of service. The weaknesses align with resource exhaustion (CWE-400) and incorrect buffer size calculation (CWE-131). Processing such an image would allow an attacker to consume large amounts of memory, leading to service interruption if the application does not handle it safely.

Affected Systems

All installations of ImageMagick before version 7.1.2‑31 are affected. The vendor/product is ImageMagick ImageMagick, and any instance running a vulnerable version remains susceptible.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity. EPSS score of < 1% and the vulnerability is not listed in the CISA KEV catalog suggest limited current exploitation activity. Exploitation would require an environment that processes UHDR images through ImageMagick, typically a web service or user‑controlled input. The likely attack vector is an application that decodes or renders UHDR images, and the inference is that an attacker would need to supply a specially crafted UHDR image to trigger uncontrolled memory allocation, potentially causing denial‑of‑service. While no public exploit has been reported, the feasibility of denial of service makes prompt mitigation advisable.

Generated by OpenCVE AI on September 23, 2026 at 14:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to ImageMagick version 7.1.2‑31 or later.
  • Ensure the ImageMagick policy files are correctly configured to prevent unauthorized UHDR encoding.
  • Monitor memory usage during image processing to detect potential denial‑of‑service attempts.

Generated by OpenCVE AI on September 23, 2026 at 14:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-131
References
Metrics threat_severity

None

threat_severity

Low


Mon, 21 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer allocation for image pixels. Attackers can bypass resource policies by processing specially crafted UHDR images, potentially causing denial of service through excessive memory allocation.
Title ImageMagick before 7.1.2-31 Policy Bypass in UHDR encoder
First Time appeared Imagemagick
Imagemagick imagemagick
Weaknesses CWE-400
CPEs cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
Vendors & Products Imagemagick
Imagemagick imagemagick
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Imagemagick Imagemagick
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T20:52:14.756Z

Reserved: 2026-09-18T10:59:45.138Z

Link: CVE-2026-93590

cve-icon Vulnrichment

Updated: 2026-09-21T16:22:47.134Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T14:19:09.943

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-93590

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-18T13:20:03Z

Links: CVE-2026-93590 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T14:15:06Z

Weaknesses
  • CWE-131

    Incorrect Calculation of Buffer Size

  • CWE-400

    Uncontrolled Resource Consumption