PT-2026-95369 · Unknown+1 · Imagemagick+1

·

CVE-2026-93590

·

Published

2026-09-18

·

Updated

2026-09-30

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ImageMagick versions prior to 7.1.2-31
Description A policy bypass exists in the UHDR encoder that fails to perform policy checks during buffer allocation for image pixels. An attacker can bypass resource policies by processing specially crafted UHDR images, which may lead to a denial of service due to excessive memory allocation.
Recommendations Update to version 7.1.2-31 or later.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93590
ECHO-8FAB-AE2F-A9ED
GHSA-7HJX-392P-F8CM
OPENSUSE-SU-2026:11854-1
OPENSUSE-SU-2026:21973-1
SUSE-SU-2026:23948-1
USN-8859-1

Affected Products

Imagemagick
Ubuntu