CVE-2026-105083
Received Received - Intake

Policy Bypass in ImageMagick via Malformed DOCTYPE

Vulnerability report for CVE-2026-105083, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: VulnCheck

Description

ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when policy.xml uses an alternate DOCTYPE. A valid DOCTYPE not ending in ']>' makes the parser consume the rest of the file, so no policy rules are applied and restricted operations become allowed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
image_magick image_magick to 7.1.2-32 (exc)
image_magick image_magick6 to 6.9.13-57 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-693 The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in ImageMagick versions before 7.1.2-32 and 6.9.13-57 allows attackers to bypass security policy rules by using a valid DOCTYPE in policy.xml that does not end with ']>'. The XML parser then skips processing policy rules, enabling restricted operations without enforcement.

Detection Guidance

To detect this vulnerability, check the ImageMagick version installed on your system. Run: convert --version or identify -version. If the version is below 7.1.2-32 or 6.9.13-57, the system is vulnerable. Additionally, inspect the policy.xml file for improper DOCTYPE declarations that do not end with ']>'. Look for files like /etc/ImageMagick-6/policy.xml or /etc/ImageMagick-7/policy.xml.

  • Check ImageMagick version: convert --version or identify -version
  • Inspect policy.xml files for DOCTYPE declarations not ending with ']>'
Impact Analysis

An attacker with local access could exploit this to perform unauthorized image operations restricted by policy.xml. This may lead to unintended image processing, potential denial-of-service, or other security breaches depending on the restricted operations.

Compliance Impact

This vulnerability could lead to unauthorized image processing or data exposure if restricted operations are bypassed. For GDPR, this may risk unauthorized data processing or access. For HIPAA, it could allow unauthorized image manipulation of protected health information.

Mitigation Strategies

Immediately upgrade ImageMagick to version 7.1.2-32 or later for ImageMagick7, or 6.9.13-57 or later for ImageMagick6. If upgrading is not possible, review and correct the policy.xml file to ensure DOCTYPE declarations end with ']>'. Remove or restrict unnecessary ImageMagick policies to minimize attack surface.

  • Upgrade ImageMagick to patched versions (7.1.2-32+ or 6.9.13-57+)
  • Correct policy.xml DOCTYPE declarations to end with ']>'
  • Remove or restrict unnecessary ImageMagick policies

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105083. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart