CVE-2026-106575
Received Received - Intake

Memory Leak in ImageMagick via Unclosed File Pointer

Vulnerability report for CVE-2026-106575, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31, a crafted Magick script can cause an opened file pointer to remain unclosed, allowing repeated processing to exhaust available file descriptors. This issue is fixed in version 7.1.2-31.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ImageMagick ImageMagick < 7.1.2-31

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-775 The product does not release a file descriptor or handle after its effective lifetime has ended, i.e., after the file descriptor/handle is no longer needed.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

ImageMagick before version 7.1.2-31 has a vulnerability where a crafted Magick script can cause an opened file pointer to remain unclosed. This leads to repeated processing exhausting available file descriptors.

Detection Guidance

Check ImageMagick version with 'magick --version' or 'convert --version'. If version is below 7.1.2-31, the system is vulnerable. Monitor for excessive file descriptor usage with 'lsof' or 'ls /proc/$$/fd' during script processing.

Impact Analysis

This vulnerability can cause denial of service by exhausting system file descriptors, potentially crashing applications or services relying on ImageMagick.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing file descriptor exhaustion through repeated processing of crafted Magick scripts. This may lead to denial-of-service conditions, affecting availability of systems handling sensitive data.

Mitigation Strategies

Upgrade ImageMagick to version 7.1.2-31 or later. If immediate upgrade is not possible, restrict execution of untrusted Magick scripts and monitor file descriptor usage.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106575. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart