Junglewise Threat Intelligence

CVE-2026-47165: ImageMagick missing authentication in distributed pixel cache

CVE-2026-47165 · Severity: medium · CVSS 4.1 · Published 2026-06-10

Technologies: Magick.NET-Q16-OpenMP-arm64 (NuGet), Magick.NET-Q16-AnyCPU (NuGet), Magick.NET-Q16-HDRI-AnyCPU (NuGet), Magick.NET-Q8-x86 (NuGet), Magick.NET-Q8-AnyCPU (NuGet), Magick.NET-Q16-arm64 (NuGet), Magick.NET-Q16-OpenMP-x64 (NuGet), Magick.NET-Q16-HDRI-arm64 (NuGet), Magick.NET-Q16-HDRI-x86 (NuGet), Magick.NET-Q16-HDRI-x64 (NuGet), Magick.NET-Q8-OpenMP-arm64 (NuGet), ImageMagick, Magick.NET-Q8-OpenMP-x64 (NuGet), Magick.NET-Q16-x64 (NuGet), Magick.NET-Q8-arm64 (NuGet), Magick.NET-Q8-x64 (NuGet), Magick.NET-Q16-x86 (NuGet), Magick.NET-Q16-HDRI-OpenMP-arm64 (NuGet). Vendors: NuGet, ImageMagick.

Executive brief

ImageMagick is a widely used open-source tool for editing and converting digital images. A security flaw in its distributed pixel cache feature could allow an unauthorized user to access sensitive image data because the system lacked a proper identity verification process. This could lead to the exposure of private information contained within processed images.

Technical details

ImageMagick's distributed pixel cache server was found to be vulnerable to information disclosure (CWE-200) due to the absence of a challenge-response authentication mechanism. This architectural omission allows actors with high privileges on the local system to potentially access cached pixel data under specific high-complexity conditions. The vulnerability affects both the 6.x and 7.x branches of the software. The issue has been addressed in versions 6.9.13-48 and 7.1.2-23 by implementing a proper authentication model for the distributed pixel cache.

Affected products

  • ImageMagick ImageMagick < 6.9.13-48, < 7.1.2-23

Timeline

  • 2026-05-19: advisory: GitHub security advisory published by maintainers
  • 2026-06-10: disclosed: CVE published to NVD dataset

References

Related threats