Junglewise Threat Intelligence

CVE-2026-45664: ImageMagick resource consumption in MNG coder

CVE-2026-45664 · Severity: medium · CVSS 5.3 · Published 2026-06-10

Technologies: Magick.NET-Q16-OpenMP-arm64 (NuGet), Magick.NET-Q16-AnyCPU (NuGet), Magick.NET-Q16-HDRI-AnyCPU (NuGet), Magick.NET-Q8-x86 (NuGet), Magick.NET-Q8-AnyCPU (NuGet), Magick.NET-Q16-arm64 (NuGet), Magick.NET-Q16-OpenMP-x64 (NuGet), Magick.NET-Q16-HDRI-OpenMP-x64 (NuGet), Magick.NET-Q16-HDRI-arm64 (NuGet), Magick.NET-Q16-HDRI-x86 (NuGet), Magick.NET-Q16-HDRI-x64 (NuGet), Magick.NET-Q8-OpenMP-arm64 (NuGet), Magick.NET-Q8-OpenMP-x64 (NuGet), Magick.NET-Q16-x64 (NuGet), Magick.NET-Q8-arm64 (NuGet), Magick.NET-Q8-x64 (NuGet), Magick.NET-Q16-x86 (NuGet), Magick.NET-Q16-HDRI-OpenMP-arm64 (NuGet), ImageMagick. Vendors: NuGet, ImageMagick.

Executive brief

ImageMagick, a widely used tool for processing and editing digital images, contains a flaw in how it handles certain image formats. An attacker can provide a specially crafted image file that bypasses security limits, causing the software to consume excessive system resources. This could lead to a denial-of-service, making the image processing service or the server hosting it unavailable to legitimate users.

Technical details

A vulnerability exists in the MNG coder of ImageMagick due to a missing check against the list limit policy. By providing a crafted MNG file, a remote attacker can force the application to read more images than permitted, leading to uncontrolled resource consumption (CWE-400), inefficient algorithmic complexity (CWE-407), or uncontrolled recursion (CWE-674). This can be exploited over the network without authentication or user interaction to cause a denial-of-service (DoS) condition. The issue is resolved in versions 6.9.13-47 and 7.1.2-22.

Affected products

  • ImageMagick ImageMagick < 6.9.13-47, < 7.1.2-22

Timeline

  • 2026-05-16: advisory: GitHub Security Advisory published
  • 2026-06-10: disclosed: CVE published to NVD

References

Related threats