CVE-2026-86425

ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the Layer method of PerlMagick. An attacker who supplies a crafted list of images can trigger memory access after deallocation, resulting in a crash (denial of service).

  • Published Sep 7, 2026
  • CVSS 4.8 medium
  • 0.1% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-86425 at the National Vulnerability Database