VYPR
Medium severity5.9NVD Advisory· Published Oct 8, 2026

CVE-2026-105824

CVE-2026-105824

Description

ImageMagick before 6.9.13-55 and 7.x before 7.1.2-30 contains a use-after-free vulnerability in the RSVG decoder when built without cairo support, triggered when a limit is hit during decoding. Attackers can supply crafted SVG files that cause a limit to be reached, leading to access of freed memory and a crash.

Affected products

2
  • ImageMagick/Imagemagickllm-fuzzy2 versions
    <6.9.13-55, <7.1.2-30+ 1 more
    • (no CPE)range: <6.9.13-55, <7.1.2-30
    • (no CPE)range: <7.1.2-30

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.