CVE-2026-105401
Received Received - Intake

Heap Buffer Overflow in ImageMagick Distributed Pixel Cache

Vulnerability report for CVE-2026-105401, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

ImageMagick before 7.1.2-31 contains a heap buffer overflow vulnerability in the distributed pixel cache server that allows connecting clients to overwrite heap memory by sending crafted data. Attackers can connect to the distributed pixel cache server and transmit malicious data to trigger a heap buffer over-write that crashes the server, causing denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ImageMagick ImageMagick 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-122 A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

ImageMagick before version 7.1.2-31 has a heap buffer overflow flaw in its distributed pixel cache server. Attackers can connect to this server and send specially crafted data to overwrite heap memory, causing the server to crash and leading to a denial of service.

Detection Guidance

To detect this vulnerability, check if your ImageMagick version is before 7.1.2-31. Run the command: identify -version or magick -version. If the output shows a version lower than 7.1.2-31, your system is vulnerable. Additionally, monitor network traffic for connections to the distributed pixel cache server port (default is 5000).

Scan for active distributed pixel cache server instances using netstat -tulnp | grep 5000 or ss -tulnp | grep 5000. Unusual connections or crashes during image processing may also indicate exploitation attempts.

Impact Analysis

This vulnerability allows attackers to remotely crash the ImageMagick distributed pixel cache server by sending malicious data. This results in service disruption and potential downtime for systems relying on this server.

Compliance Impact

This vulnerability primarily causes denial of service by crashing the distributed pixel cache server, which may disrupt services handling sensitive data. While not directly violating GDPR or HIPAA, such disruptions could impact availability requirements under these regulations. Organizations must ensure affected systems are patched to maintain compliance with availability and security controls.

Mitigation Strategies

Immediately upgrade ImageMagick to version 7.1.2-31 or later. Disable the distributed pixel cache server if not needed by setting the environment variable MAGICK_OPTIONS=disable-pixel-cache-server=1 or removing it from configuration files.

Restrict network access to the distributed pixel cache server port (5000) using firewalls. Monitor system logs for crashes or suspicious activity related to ImageMagick processes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105401. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart