Medium severity5.9NVD Advisory· Published Oct 8, 2026
CVE-2026-105824
CVE-2026-105824
Description
ImageMagick before 6.9.13-55 and 7.x before 7.1.2-30 contains a use-after-free vulnerability in the RSVG decoder when built without cairo support, triggered when a limit is hit during decoding. Attackers can supply crafted SVG files that cause a limit to be reached, leading to access of freed memory and a crash.
Affected products
2<6.9.13-55, <7.1.2-30+ 1 more
- (no CPE)range: <6.9.13-55, <7.1.2-30
- (no CPE)range: <7.1.2-30
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.