CVE-2026-102635
Received Received - Intake

Heap Memory Disclosure in ImageMagick GIF Decoder

Vulnerability report for CVE-2026-102635, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulnCheck

Description

ImageMagick versions before 7.1.2-32 and 6.9.13-57 contain uninitialized heap memory disclosure in the GIF decoder's application extension handler in coders/gif.c. Attackers can craft malicious GIF files that cause the number parser to read uninitialized heap memory and store contents as image metadata, disclosing sensitive heap information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
imagemagick image_magick to 7.1.2-32 (exc)
imagemagick image_magick to 6.9.13-57 (exc)
image_magick image_magick to 7.1.2-32 (exc)
image_magick image_magick to 6.9.13-57 (exc)
image_magick image_magick From 0|end_excluding=6.9.13-57 (exc)
image_magick image_magick From 7.0.0-0|end_excluding=7.1.2-32 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-908 The product uses or accesses a resource that has not been initialized.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an uninitialized heap memory disclosure issue in ImageMagick's GIF decoder. It occurs in versions before 7.1.2-32 and 6.9.13-57. Attackers can create malicious GIF files that cause the software to read uninitialized heap memory during processing. This exposed memory is then stored as image metadata, potentially leaking sensitive information from the application's memory space.

Detection Guidance

To detect this vulnerability, check the installed version of ImageMagick using the command: identify -version or convert -version. If the output shows a version before 7.1.2-32 or 6.9.13-57, the system is vulnerable. Additionally, monitor network traffic for unusual GIF file processing requests.

Impact Analysis

If you process untrusted GIF files with vulnerable ImageMagick versions, attackers could extract sensitive data from your system's memory. This might include passwords, encryption keys, or other confidential information. The vulnerability could also cause application crashes or denial of service when processing specially crafted files.

Compliance Impact

This vulnerability could lead to unauthorized disclosure of personal or sensitive data, violating GDPR's data protection requirements and HIPAA's security rules for protected health information. Organizations processing GIF files with vulnerable versions may face compliance violations, potential fines, and reputational damage due to information disclosure incidents.

Mitigation Strategies

Immediately update ImageMagick to version 7.1.2-32 or later for ImageMagick 7, or 6.9.13-57 or later for ImageMagick 6. If updating is not possible, restrict processing of GIF files or disable the GIF decoder in ImageMagick's policy configuration.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102635. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart