PT-2026-107985 · Imagemagick · Imagemagick

·

CVE-2026-105826

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
ImageMagick before 6.9.13-55 and 7.x before 7.1.2-30 contains a security policy bypass in the MAT decoder, which does not enforce configured temporary file size limits when reading highly compressed data. Attackers can supply a crafted MAT image whose decompressed data is written to temporary files larger than the policy allows, consuming disk resources.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105826

Affected Products

Imagemagick