ImageMagick
14 known vulnerabilities in ImageMagick, 1 actively exploited, with patch priority, exploit likelihood and the news covering them.
Recently exploited
- CVE-2016-3714 CVSS 8.4 high · actively exploited ImageMagick Improper Input Validation Vulnerability
Latest vulnerabilities
- CVE-2026-105083 CVSS 1.8 low ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy…
- CVE-2026-102635 CVSS 6.3 medium ImageMagick versions before 7.1.2-32 and 6.9.13-57 contain uninitialized heap memory disclosure in the GIF decoder's application extension…
- CVE-2026-93590 CVSS 6.3 medium ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer…
- CVE-2026-93589 CVSS 6.3 medium ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for ticks per second in…
- CVE-2026-93588 CVSS 2.3 low ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder. When the coder reaches a memory…
- CVE-2026-93587 CVSS 4.8 medium ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CUBE and HALD)…
- CVE-2026-93586 CVSS 2.1 low ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, caused by a pointer…
- CVE-2026-86425 CVSS 4.8 medium ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the Layer method of PerlMagick. An…
- CVE-2026-86424 CVSS 2.0 low ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows…
- CVE-2026-86423 CVSS 4.8 medium ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the GetList method of PerlMagick. A…
- CVE-2026-86422 CVSS 1.0 low ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers…
- CVE-2026-86421 CVSS 6.3 medium ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation…
- CVE-2026-86420 CVSS 6.3 medium ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails…
- CVE-2016-3714 CVSS 8.4 high · actively exploited ImageMagick Improper Input Validation Vulnerability