CVE-2026-106569
Received Received - Intake

Memory Corruption in ImageMagick via ASE Decoder

Vulnerability report for CVE-2026-106569, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, missing validation and resource checks in the ASE decoder allow a crafted ASE image to cause a crash or a long-running operation. This issue is fixed in version 7.1.2-32.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ImageMagick ImageMagick < 7.1.2-32

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
CWE-789 The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in ImageMagick prior to version 7.1.2-32 involves missing validation and resource checks in the ASE decoder. A crafted ASE image can cause crashes or long-running operations due to improper handling of cel data and memory allocation.

Detection Guidance

To detect this vulnerability, check the installed version of ImageMagick using the command: convert --version or identify -version. If the version is below 7.1.2-32, the system is vulnerable. Additionally, monitor for crashes or long-running processes when processing ASE images.

Impact Analysis

The vulnerability can lead to denial of service by crashing ImageMagick or causing it to run indefinitely. It may also consume excessive system resources due to unchecked memory allocation, potentially affecting system performance.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling denial-of-service attacks through crashes or resource exhaustion. GDPR requires systems to maintain availability, while HIPAA mandates safeguards against disruptions. The lack of resource checks may lead to prolonged processing, affecting system reliability and availability.

Mitigation Strategies

Upgrade ImageMagick to version 7.1.2-32 or later immediately. If upgrading is not possible, disable the ASE decoder by removing or renaming the ase.c file in the coders directory. Restrict access to ImageMagick processing for untrusted users.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106569. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart