CVE-2026-86420
Received Received - Intake

Memory Exhaustion in ImageMagick Due to OpenPixelCache Failure

Vulnerability report for CVE-2026-86420, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-07

Last updated on: 2026-09-07

Assigner: VulnCheck

Description

ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-07
Last Modified
2026-09-07
Generated
2026-09-07
AI Q&A
2026-09-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
imagemagick imagemagick to 7.1.2-30 (exc)
imagemagick imagemagick to 6.9.13-55 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in ImageMagick occurs when an operation inside OpenPixelCache fails, preventing the memory budget from being lowered. Repeated failures can exhaust the process memory budget, leading to a denial of service.

Detection Guidance

To detect this vulnerability, check the installed version of ImageMagick using the command: convert --version or identify --version. If the version is below 7.1.2-30 or 6.9.13-55, the system is vulnerable. Monitor system memory usage for unexpected spikes during ImageMagick operations.

Impact Analysis

An attacker could exploit this to crash the ImageMagick process by repeatedly triggering memory exhaustion, causing a denial of service. This may disrupt services relying on ImageMagick for image processing.

Compliance Impact

This vulnerability primarily impacts system availability by causing denial of service through memory exhaustion. It does not directly affect data confidentiality or integrity, which are key concerns for GDPR and HIPAA. However, prolonged downtime could indirectly impact compliance by disrupting access to personal or health data processing systems.

Mitigation Strategies

Immediately upgrade ImageMagick to version 7.1.2-30 or later for ImageMagick 7, or 6.9.13-55 or later for ImageMagick 6. If upgrading is not possible, restrict access to ImageMagick commands or disable vulnerable features until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86420. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart