CVE-2026-105402
Received Received - Intake

ImageMagick XMP Profile Denial of Service Vulnerability

Vulnerability report for CVE-2026-105402, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

ImageMagick before 7.1.2-31 contains a denial of service vulnerability that allows attackers to disrupt processing by supplying a crafted XMP profile. Attackers can embed a malicious XMP profile that triggers a failure when determining the numerator and denominator, crashing or hanging image processing.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ImageMagick ImageMagick 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a denial of service issue in ImageMagick versions before 7.1.2-31. Attackers can exploit it by providing a specially crafted XMP profile that causes the software to fail when calculating numerator and denominator values during parsing. This leads to crashes or hangs in image processing operations.

Detection Guidance

To detect this vulnerability, check the installed version of ImageMagick using the command 'convert --version' or 'magick --version'. If the version is below 7.1.2-31, the system is vulnerable. Monitor for crashes or hangs during image processing tasks.

Impact Analysis

This vulnerability allows remote attackers to disrupt image processing by causing crashes or hangs. It does not require privileges or user interaction, meaning any system processing images with vulnerable ImageMagick versions could be affected. This may lead to service disruptions or degraded performance.

Compliance Impact

This vulnerability primarily causes denial of service by crashing or hanging image processing, which could disrupt services handling sensitive data. While not directly violating GDPR or HIPAA, prolonged downtime might impact availability requirements under these regulations. Organizations must ensure timely patching to maintain compliance with data processing integrity and availability principles.

Mitigation Strategies

Immediately upgrade ImageMagick to version 7.1.2-31 or later. If upgrading is not possible, restrict network access to ImageMagick processing functions and disable XMP profile parsing if supported.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105402. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart