Executive brief
ImageMagick is a widely-used image processing library that powers web applications, content management systems, and desktop tools. A flaw in its memory management fails to properly release allocated memory when pixel cache operations fail, allowing an attacker to exhaust available system memory through repeated requests and crash the application or service.
Technical details
The vulnerability is a resource exhaustion / memory leak (CWE-400, CWE-401) in ImageMagick's OpenPixelCache subsystem. When an operation inside the pixel cache fails, the memory budget allocated for that operation is not properly decremented, causing the internal accounting to become inaccurate. An attacker can trigger repeated failures to exhaust the process memory budget, resulting in a denial of service. The flaw affects ImageMagick versions before 7.1.2-30 and before 6.9.13-55. No authentication or user interaction is required; the attack is network-accessible but requires high complexity to trigger reliably. Patches are available in versions 7.1.2-30 and 6.9.13-55 or later.
Affected products
- ImageMagick ImageMagick before 7.1.2-30 and before 6.9.13-55
Timeline
- 2026-08-23: disclosed: GitHub security advisory GHSA-4mwf-mggw-29vp published
- 2026-09-07: advisory: CVE-2026-86420 published in NVD
- 2026: patched: Patches released in versions 7.1.2-30 and 6.9.13-55