CVE-2026-105405
Received Received - Intake

Invalid Memory Free in ImageMagick

Vulnerability report for CVE-2026-105405, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 contains an invalid memory free vulnerability in the MVG decoder. Attackers can supply a crafted MVG image for processing to trigger the invalid free and crash the application, causing a denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ImageMagick ImageMagick 0
ImageMagick ImageMagick 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-763 The product attempts to return a memory resource to the system, but it calls the wrong release function or calls the appropriate release function incorrectly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an invalid memory free issue in the MVG decoder of ImageMagick versions before 7.1.2-31 and 6.9.13-56. Attackers can exploit it by providing a specially crafted MVG image, which triggers an invalid memory free operation. This causes the application to crash, leading to a denial of service.

Detection Guidance

To detect this vulnerability, check the installed version of ImageMagick on your system. Run the command 'convert --version' or 'magick --version' to see the version number. If the version is below 7.1.2-31 or 6.9.13-56, your system is vulnerable.

Impact Analysis

This vulnerability can cause the ImageMagick application to crash, making it unavailable for use. Since it can be exploited remotely without privileges or user interaction, attackers could disrupt services that rely on ImageMagick for image processing.

Compliance Impact

This vulnerability primarily impacts system availability by causing crashes through crafted MVG images. While it does not directly expose data, denial of service could disrupt services handling sensitive data, potentially violating availability requirements in GDPR and HIPAA.

Mitigation Strategies

Immediately update ImageMagick to version 7.1.2-31 or later for version 7.x, or 6.9.13-56 or later for version 6.x. If updating is not possible, consider disabling the MVG decoder or restricting access to ImageMagick processing until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105405. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart