CVE-2026-105825
Received Received - Intake

ImageMagick XMP Profile Denial of Service Vulnerability

Vulnerability report for CVE-2026-105825, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

ImageMagick before 6.9.13-55 and 7.x before 7.1.2-30 contains a denial of service vulnerability in its handling of XMP profiles, where a crafted profile terminates the process instead of raising an exception. Attackers can supply images with malicious XMP profiles to crash applications that process them using ImageMagick.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ImageMagick ImageMagick 0
ImageMagick ImageMagick 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

ImageMagick versions before 6.9.13-55 and 7.x before 7.1.2-30 have a denial of service vulnerability in XMP profile handling. A crafted XMP profile can terminate the process instead of raising an exception, causing applications using ImageMagick to crash when processing malicious images.

Detection Guidance

To detect this vulnerability, check the version of ImageMagick installed on your system. Compare it against versions 6.9.13-55 or 7.1.2-30. Use commands like 'convert --version' or 'magick --version' to check the installed version.

Impact Analysis

This vulnerability allows attackers to crash applications that process images with malicious XMP profiles. This can lead to service disruption, downtime, or denial of service for users relying on those applications.

Compliance Impact

This vulnerability primarily causes denial of service by crashing applications processing images with malicious XMP profiles. It does not directly impact data confidentiality or integrity, which are key focus areas for GDPR and HIPAA. However, repeated crashes could disrupt services handling sensitive data, potentially leading to compliance issues if critical systems become unavailable.

Mitigation Strategies

Immediately update ImageMagick to version 6.9.13-55 or 7.1.2-30 or later. Avoid processing images from untrusted sources until the update is applied. Monitor for crashes in applications using ImageMagick.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105825. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart