CVE-2026-105399
Received Received - Intake

ImageMagick MVG Decoder Denial of Service Vulnerability

Vulnerability report for CVE-2026-105399, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 contains a denial of service vulnerability in the MVG decoder caused by a missing limit check. Attackers can supply a crafted MVG image that triggers a long-running decoding operation, consuming excessive CPU resources and stalling image processing.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ImageMagick ImageMagick 0
ImageMagick ImageMagick 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a denial of service issue in ImageMagick's MVG decoder caused by a missing limit check. Attackers can exploit it by providing a specially crafted MVG image that triggers an excessively long decoding process, consuming excessive CPU resources and stalling image processing.

Detection Guidance

Check ImageMagick version with 'convert --version' or 'magick --version'. Affected versions are before 7.1.2-31 and 6.9.13-56. Monitor CPU usage spikes during image processing tasks.

Impact Analysis

This vulnerability can cause system slowdowns or complete stalls in image processing due to high CPU usage. It may disrupt services relying on ImageMagick for image manipulation, leading to degraded performance or unavailability.

Compliance Impact

This vulnerability primarily impacts system availability by causing excessive CPU consumption through crafted MVG images. While it does not directly expose or leak data, prolonged system unavailability could interfere with compliance requirements for timely data processing or access, particularly under GDPR's data integrity principles or HIPAA's availability standards.

Mitigation Strategies

Upgrade ImageMagick to patched versions 7.1.2-31 or later for version 7.x, or 6.9.13-56 or later for version 6.x. Restrict access to image processing functions if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105399. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart