CVE-2026-107209
Received Received - Intake

Double Free in ImageMagick via RSVG Image Handling

Vulnerability report for CVE-2026-107209, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, when ImageMagick is built without Cairo support, a crafted RSVG image that reaches a resource limit can cause the RSVG decoder to free image state twice and then use freed memory, crashing the process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ImageMagick ImageMagick < 6.9.13-55
ImageMagick ImageMagick >= 7.0.0, < 7.1.2-30

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-416 The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
CWE-415 The product calls free() twice on the same memory address.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects ImageMagick, a software for editing digital images. When ImageMagick is built without Cairo support, a specially crafted RSVG image can cause the program to free image state memory twice and then use that freed memory. This leads to a crash of the process due to memory corruption.

Detection Guidance

To detect this vulnerability, check the ImageMagick version installed on your system. Run: convert --version or identify --version. If the version is below 7.1.2-30 or 6.9.13-55, the system is vulnerable. Additionally, inspect logs for crashes during SVG image processing.

Impact Analysis

If you use ImageMagick without Cairo support and process a malicious RSVG image, the program may crash. This could disrupt image processing tasks or services relying on ImageMagick. However, it does not allow unauthorized access or data theft.

Compliance Impact

This vulnerability primarily causes service disruptions rather than data breaches. Compliance impact would depend on whether the crash leads to unavailability of systems handling personal or sensitive data. No direct data exposure is indicated.

Mitigation Strategies

Upgrade ImageMagick to version 7.1.2-30 or later if using 7.x, or to 6.9.13-55 or later if using 6.x. This fixes the issue by addressing the double-free and use-after-free vulnerabilities in the RSVG decoder.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107209. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart