CVE-2026-86420
ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service.
- Published Sep 7, 2026
- CVSS 6.3 medium
- 0.3% chance of exploitation in the next 30 days (EPSS)
- A fix is available