📦 Imagemagick

by Imagemagick

🔍 What is Imagemagick?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-34152

CRITICAL CVSS 9.8 May 30, 2023

CVE-2023-34152 is a critical remote code execution vulnerability in ImageMagick's OpenBlob function when compiled with --enable-pipes configuration. Attackers can exploit this by processing malicious ...

CVE-2026-25985

HIGH CVSS 7.5 Feb 24, 2026

ImageMagick versions prior to 7.1.2-15 and 6.9.13-40 contain a memory allocation vulnerability in SVG processing. A malicious SVG file with a crafted element can trigger an attempt to allocate approxi...

CVE-2026-25967

HIGH CVSS 7.4 Feb 24, 2026

This vulnerability is a stack-based buffer overflow in ImageMagick's FTXT image reader, allowing crafted FTXT files to cause out-of-bounds writes on the stack, potentially leading to crashes or arbitr...

CVE-2026-25965

HIGH CVSS 8.6 Feb 24, 2026

ImageMagick's path security policy enforcement occurs before filesystem path resolution, allowing path traversal attacks to bypass policy rules like '/etc/*'. This enables local file disclosure (LFI) ...

CVE-2026-25794

HIGH CVSS 8.2 Feb 24, 2026

This vulnerability in ImageMagick allows attackers to trigger an integer overflow when processing large UHDR images, leading to heap buffer overflow and potential arbitrary code execution. Any system ...

CVE-2026-24481

HIGH CVSS 7.5 Feb 24, 2026

ImageMagick versions before 7.1.2-15 and 6.9.13-40 have a heap information disclosure vulnerability in their PSD format handler. When processing specially crafted ZIP-compressed PSD files, uninitializ...

CVE-2026-24485

HIGH CVSS 7.5 Feb 24, 2026

This vulnerability in ImageMagick allows attackers to cause denial of service by exploiting an infinite loop in PCD file processing. When ImageMagick processes a specially crafted PCD file without a v...

CVE-2026-23876

HIGH CVSS 8.1 Jan 20, 2026

A heap buffer overflow vulnerability in ImageMagick's XBM image decoder allows attackers to write controlled data beyond allocated memory boundaries when processing malicious image files. This affects...

CVE-2025-66628

HIGH CVSS 7.5 Dec 10, 2025

ImageMagick's TIM image parser contains an integer overflow vulnerability that allows attackers to trigger out-of-bounds memory reads by providing specially crafted TIM images. This affects ImageMagic...

CVE-2025-55298

HIGH CVSS 7.5 Aug 26, 2025

A format string vulnerability in ImageMagick's InterpretImageFilename function allows attackers to overwrite arbitrary memory regions by passing unsanitized user input to FormatLocaleString. This can ...

CVE-2025-55154

HIGH CVSS 8.8 Aug 13, 2025

This vulnerability in ImageMagick allows integer overflow during PNG/MNG image processing, leading to memory corruption. Attackers can exploit this by crafting malicious images to potentially execute ...

CVE-2025-55004

HIGH CVSS 7.6 Aug 13, 2025

ImageMagick versions before 7.1.2-1 contain a heap-buffer overflow vulnerability in the MNG image format parser that can leak memory contents into output images. This affects any system or application...

CVE-2025-53101

HIGH CVSS 7.4 Jul 14, 2025

A stack overflow vulnerability in ImageMagick's mogrify command allows attackers to crash the application or potentially execute arbitrary code by providing malicious filename templates with multiple ...

CVE-2025-53015

HIGH CVSS 7.5 Jul 14, 2025

ImageMagick versions before 7.1.2-0 contain an infinite loop vulnerability when processing XMP files during conversion. This can cause denial of service through resource exhaustion. Any system using v...

CVE-2024-41817

HIGH CVSS 7.0 Jul 29, 2024

CVE-2024-41817 is a path injection vulnerability in ImageMagick's AppImage version where empty paths in MAGICK_CONFIGURE_PATH and LD_LIBRARY_PATH environment variables allow loading malicious configur...

CVE-2022-48541

HIGH CVSS 7.1 Aug 22, 2023

A memory leak vulnerability in ImageMagick allows remote attackers to cause denial of service by triggering the 'identify -help' command. This affects systems running vulnerable versions of ImageMagic...

CVE-2021-40211

HIGH CVSS 7.5 Aug 22, 2023

This vulnerability in ImageMagick allows attackers to cause a denial of service (DoS) or potentially execute arbitrary code via a division by zero error when processing Enhanced Metafile (EMF) images....

CVE-2022-32545

HIGH CVSS 7.8 Jun 16, 2022

This CVE-2022-32545 is an integer overflow vulnerability in ImageMagick's PSD file parser. When processing specially crafted or untrusted PSD files, it can cause undefined behavior leading to applicat...

CVE-2022-32547

HIGH CVSS 7.8 Jun 16, 2022

This CVE is an alignment vulnerability in ImageMagick's property.c file where misaligned memory access for double and float types can cause undefined behavior. It affects applications that process unt...

CVE-2021-3610

HIGH CVSS 7.5 Feb 24, 2022

This heap-based buffer overflow vulnerability in ImageMagick's TIFF image processing allows attackers to crash applications or potentially execute arbitrary code by providing malicious TIFF files. It ...

CVE-2021-20310

HIGH CVSS 7.5 May 11, 2021

This CVE describes a division-by-zero vulnerability in ImageMagick's ConvertXYZToJzazbz() function in MagickCore/colorspace.c, which can be triggered by processing a specially crafted image file. It m...

CVE-2021-20312

HIGH CVSS 7.5 May 11, 2021

This CVE describes an integer overflow vulnerability in ImageMagick's thumbnail generation function. Attackers can craft malicious image files that trigger undefined behavior when processed by applica...

CVE-2026-27798

MEDIUM CVSS 4.0 Feb 26, 2026

ImageMagick versions prior to 7.1.2-15 and 6.9.13-40 contain a heap buffer over-read vulnerability when processing images with small dimensions using the -wavelet-denoise operator. This could allow at...

CVE-2026-26983

MEDIUM CVSS 5.3 Feb 24, 2026

This CVE describes a use-after-free vulnerability in ImageMagick's MSL interpreter when processing invalid <map> elements, causing crashes. It affects ImageMagick versions before 7.1.2-15 and 6.9.13-4...

CVE-2026-26284

MEDIUM CVSS 6.5 Feb 24, 2026

ImageMagick versions before 7.1.2-15 and 6.9.13-40 contain an out-of-bounds read vulnerability when processing Huffman-coded data in PCD files due to improper boundary checking. This could allow attac...

CVE-2026-26066

MEDIUM CVSS 6.2 Feb 24, 2026

ImageMagick versions before 7.1.2-15 and 6.9.13-40 contain a vulnerability where specially crafted IPTC profile data can trigger an infinite loop when processed with the IPTCTEXT function. This affect...

CVE-2026-25971

MEDIUM CVSS 6.2 Feb 24, 2026

ImageMagick versions before 7.1.2-15 and 6.9.13-40 contain a vulnerability where the software fails to detect circular references between two MSL (Magick Scripting Language) files, leading to a stack ...

CVE-2026-25983

MEDIUM CVSS 5.3 Feb 24, 2026

This CVE describes a heap-use-after-free vulnerability in ImageMagick's MSL (Magick Scripting Language) parser. Attackers can exploit this by crafting malicious MSL scripts to potentially execute arbi...

CVE-2026-25987

MEDIUM CVSS 5.3 Feb 24, 2026

ImageMagick contains a heap buffer over-read vulnerability in its MAP image decoder that could allow attackers to cause crashes or leak memory by processing specially crafted MAP files. This affects a...

CVE-2026-25969

MEDIUM CVSS 5.3 Feb 24, 2026

A memory leak vulnerability exists in ImageMagick's ASHLAR image coder when processing certain images. This could allow attackers to cause denial of service by exhausting system memory through repeate...

CVE-2026-25897

MEDIUM CVSS 6.5 Feb 24, 2026

An integer overflow vulnerability in ImageMagick's SUN decoder allows attackers to trigger an out-of-bounds heap write on 32-bit systems. This can potentially lead to remote code execution or denial o...

CVE-2026-25796

MEDIUM CVSS 5.3 Feb 24, 2026

This CVE describes a memory leak vulnerability in ImageMagick's STEGANO image decoder. When processing specially crafted steganographic images, the software fails to free allocated memory on certain e...

CVE-2026-25798

MEDIUM CVSS 5.3 Feb 24, 2026

A NULL pointer dereference vulnerability in ImageMagick's ClonePixelCacheRepository function allows remote attackers to crash applications by providing a specially crafted image file, causing denial o...

CVE-2026-25637

MEDIUM CVSS 5.3 Feb 24, 2026

A memory leak vulnerability in ImageMagick's ASHLAR image writer allows attackers to cause denial of service by exhausting process memory through crafted images. This affects all systems running vulne...

CVE-2026-25576

MEDIUM CVSS 5.1 Feb 24, 2026

ImageMagick versions prior to 7.1.2-15 and 6.9.13-40 contain a heap buffer over-read vulnerability when processing raw image formats. Attackers can trigger out-of-bounds memory reads by providing imag...

CVE-2026-23952

MEDIUM CVSS 6.5 Jan 22, 2026

ImageMagick versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL parser when processing <comment> tags before images are loaded. This can cause denial of service (DoS) t...

CVE-2026-22770

MEDIUM CVSS 6.5 Jan 20, 2026

ImageMagick versions before 7.1.2-13 contain a memory corruption vulnerability in the BilateralBlurImage method. When memory allocation fails, an uninitialized pointer is released, potentially causing...

CVE-2026-23874

MEDIUM CVSS 5.5 Jan 20, 2026

ImageMagick versions before 7.1.2-13 have a stack overflow vulnerability in the MSL (Magick Scripting Language) <write> command when writing to MSL format, caused by infinite recursion. This can lead ...

CVE-2025-68618

MEDIUM CVSS 5.3 Dec 30, 2025

ImageMagick versions before 7.1.2-12 contain a denial-of-service vulnerability when processing malicious SVG files. Attackers can cause the application to crash by submitting specially crafted SVG ima...

CVE-2025-68950

MEDIUM CVSS 4.0 Dec 30, 2025

ImageMagick versions before 7.1.2-12 contain a denial-of-service vulnerability where circular references between two MVG (Magick Vector Graphics) files cause a stack overflow. This affects any system ...

CVE-2025-69204

MEDIUM CVSS 5.3 Dec 30, 2025

ImageMagick versions before 7.1.2-12 contain an integer overflow vulnerability in the WriteSVGImage function that can trigger a buffer overflow. This allows attackers to cause denial of service (DoS) ...

CVE-2025-65955

MEDIUM CVSS 4.9 Dec 2, 2025

This CVE describes a double-free vulnerability in ImageMagick's Magick++ layer when Options::fontFamily is called with an empty string. This can lead to crashes, heap corruption, or potential remote c...

CVE-2025-62594

MEDIUM CVSS 4.7 Oct 27, 2025

ImageMagick versions before 7.1.2-8 contain a vulnerability in the CLAHEImage function where zero tile dimensions cause unsigned integer underflow and division-by-zero errors. This leads to out-of-bou...

CVE-2025-68469

LOW CVSS 3.3 Dec 18, 2025

ImageMagick versions before 7.1.1-14 contain a heap-based buffer overflow vulnerability (CWE-122) when processing specially crafted TIFF files. This can cause the application to crash, potentially lea...