CVE-2026-106570
Received Received - Intake

Denial of Service in ImageMagick via Pixel Cache Exhaustion

Vulnerability report for CVE-2026-106570, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, an unauthenticated adjacent-network client can repeatedly connect to the distributed pixel cache server and exhaust its available connections, causing denial of service. This issue is fixed in version 7.1.2-32.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ImageMagick ImageMagick < 7.1.2-32

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in ImageMagick involves a flaw in the distributed pixel cache server where an unauthenticated attacker can repeatedly connect and exhaust available connections, causing a denial of service. The issue was fixed in version 7.1.2-32 by improving socket communication handling with new functions like dpc_receive and dpc_receive_deadline, which include timeout and error management.

Detection Guidance

Check if ImageMagick version is below 7.1.2-32. Monitor network connections to the distributed pixel cache server for unusual activity or connection exhaustion. Use commands like netstat -an | grep <port> to check active connections.

Impact Analysis

If exploited, this vulnerability could cause the distributed pixel cache server to become unavailable, leading to service disruption. It requires no privileges or user interaction and can be exploited remotely with low complexity, making it a potential risk for systems using vulnerable ImageMagick versions.

Compliance Impact

This vulnerability primarily causes denial of service by exhausting connections to the distributed pixel cache server. It does not directly impact data confidentiality or integrity, which are key concerns for GDPR and HIPAA. However, prolonged denial of service could indirectly affect compliance by disrupting access to critical systems handling personal or health data.

Mitigation Strategies

Upgrade ImageMagick to version 7.1.2-32 or later. Disable the distributed pixel cache server if not needed. Restrict network access to the cache server port.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106570. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart