Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

ImageMagick — Vulnerabilities & Security Advisories 158

Browse all 158 CVE security advisories affecting ImageMagick. AI-powered Chinese analysis, POCs, and references for each vulnerability.

ImageMagick is a widely used open-source software suite for creating, editing, and composing bitmap images, serving as a foundational backend for numerous web applications and content management systems. Its extensive feature set and default configuration have historically introduced significant security risks, resulting in nearly one hundred recorded Common Vulnerabilities and Exposures. The most prevalent issues involve Remote Code Execution (RCE) and Denial of Service (DoS), often triggered by maliciously crafted image files that exploit buffer overflows or unsafe command-line argument parsing. While Cross-Site Scripting (XSS) and privilege escalation vulnerabilities have also been documented, RCE remains the primary threat vector due to the tool’s ability to process complex image formats. Major incidents, such as the "ImageTragick" vulnerability, highlighted critical flaws in how the software handles input, prompting widespread adoption of stricter security policies and configuration hardening across the industry to mitigate these inherent risks.

Top products by ImageMagick: ImageMagick
CVE IDTitleCVSSSeverityPublished
CVE-2026-61870 ImageMagick before 7.1.2-26 Memory Leak via VIFF Encoder — ImageMagickCWE-401 2.9 Low2026-07-11
CVE-2026-61861 ImageMagick before 7.1.2-26 Use-After-Free in FormatMagickCaption — ImageMagickCWE-416 3.7 Low2026-07-11
CVE-2026-61858 ImageMagick before 7.1.2-26 Policy Bypass via APNG encoder — ImageMagickCWE-59 3.3 Low2026-07-11
CVE-2026-61857 ImageMagick before 7.1.2-26 Heap Use-After-Free via XMP — ImageMagickCWE-252 3.7 Low2026-07-11
CVE-2026-61465 ImageMagick before 7.1.2-26 Memory Allocation Policy Bypass — ImageMagickCWE-770 3.3 Low2026-07-11
CVE-2026-56372 ImageMagick - Heap Buffer Overflow Read via Unrecognized Magnify Method — ImageMagickCWE-122 3.3 Low2026-07-11
CVE-2026-56373 ImageMagick - Use-After-Free Write in PDB Decoder — ImageMagickCWE-416 3.7 Low2026-07-10
CVE-2026-56366 ImageMagick - Memory Leak in META Reader APP1JPEG Error Path — ImageMagickCWE-401 3.3 Low2026-07-10
CVE-2026-56374 ImageMagick - Heap Buffer Overflow in FTXT Encoder via format Parameter — ImageMagickCWE-125 3.3 Low2026-07-08
CVE-2026-56362 ImageMagick - Heap-buffer-overflow Read in GetPixelIndex via OpenPixelCache Metadata Desynchronization — ImageMagickCWE-125 3.3 Low2026-07-08
CVE-2026-55597 ImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of arguments — ImageMagickCWE-682 5.5 Medium2026-07-01
CVE-2026-55595 ImageMagick: Infinite Loop in connected-components when providing invalid arguments — ImageMagickCWE-400 4.7 Medium2026-07-01
CVE-2026-55594 ImageMagick: Stack Overflow in MVG decoder due to missing depth check. — ImageMagickCWE-400 5.3 Medium2026-07-01
CVE-2026-55577 ImageMagick: Heap Buffer Overflow in ImageMagick MVG decoder — ImageMagickCWE-754 5.9 Medium2026-07-01
CVE-2026-55510 ImageMagick: Use-After-Free in crafted 8BIM when identifying an image — ImageMagickCWE-416 5.5 Medium2026-07-01
CVE-2026-53467 ImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchanged — ImageMagickCWE-908 5.3 Medium2026-07-01
CVE-2026-53466 ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow — ImageMagickCWE-190 6.5 Medium2026-07-01
CVE-2026-55628 ImageMagick: Policy Bypass in concatenate operation due to missing checks — ImageMagickCWE-73 5.5 Medium2026-07-01
CVE-2026-56377 ImageMagick - Policy Bypass via Incorrect Path Validation — ImageMagickCWE-22 3.3 Low2026-06-30
CVE-2026-56369 ImageMagick - Information Disclosure via AES-CTR Nonce Reuse in PasskeyEncipherImage — ImageMagickCWE-323 3.7 Low2026-06-30
CVE-2026-56364 ImageMagick - Memory Leak in LoadOpenCLDeviceBenchmark() via Malformed XML — ImageMagickCWE-401 1.9 Low2026-06-30
CVE-2026-56365 ImageMagick - Memory Leak in PNG Encoder via MNG Image Writing — ImageMagickCWE-401 3.7 Low2026-06-30
CVE-2026-56363 ImageMagick - Division by Zero in Binomial Kernel Processing — ImageMagickCWE-190 3.3 Low2026-06-30
CVE-2026-56361 ImageMagick - Heap Buffer Overflow via Off-by-One in Morphology Processing — ImageMagickCWE-125 3.3 Low2026-06-30
CVE-2026-56370 ImageMagick - Out-of-bounds Access in ConnectedComponentsImage via connected-components Artifact — ImageMagickCWE-125 3.3 Low2026-06-24
CVE-2026-56368 ImageMagick - Memory Leak in Raw Pixel Data Coders — ImageMagickCWE-401 3.7 Low2026-06-24
CVE-2026-56376 ImageMagick - Heap Use-After-Free in Meta Coder — ImageMagickCWE-416 3.7 Low2026-06-23
CVE-2026-56379 ImageMagick - Command Injection via SVG Decoder — ImageMagickCWE-116 8.1 High2026-06-23
CVE-2026-56371 ImageMagick - Memory Leak in TXT File Processing via Texture Attribute — ImageMagickCWE-401 5.3 Medium2026-06-23
CVE-2026-56378 ImageMagick - Heap Out-of-Bounds Read in PCD Decoder — ImageMagickCWE-125 3.7 Low2026-06-21

This page lists every published CVE security advisory associated with ImageMagick. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.