CVE-2026-106579
Received
Received - Intake
Policy Bypass in ImageMagick via Crafted Image
Vulnerability report for CVE-2026-106579, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-07
Last updated on: 2026-10-07
Assigner: GitHub, Inc.
Description
Description
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can bypass an ImageMagick security policy that uses coder as its domain, potentially allowing data prohibited by the policy to be read. This issue is fixed in versions 7.1.2-31 and 6.9.13-56.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ImageMagick | ImageMagick | < 6.9.13-56 |
| ImageMagick | ImageMagick | >= 7.0.0, < 7.1.2-31 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-551 | If a web server does not fully parse requested URLs before it examines them for authorization, it may be possible for an attacker to bypass authorization protection. |