{"id":"CVE-2026-105083","title":"ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when policy.xml uses an alternate DOCTYPE","summary":"ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when policy.xml uses an alternate DOCTYPE. A valid DOCTYPE not ending in ']>' makes the parser …","severity":"low","cvss":3.9,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L","cwe":["CWE-693","CWE-1286"],"vendor":"ImageMagick","product":"ImageMagick","affected":["ImageMagick >= 7.0.0-0 < 7.1.2-32","ImageMagick < 6.9.13-57"],"published":"2026-10-03","updated":"2026-10-03","sourceUpdated":"2026-10-03T02:17:18.170","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105083","references":[{"url":"https://github.com/ImageMagick/ImageMagick","label":"disclosure@vulncheck.com"},{"url":"https://github.com/ImageMagick/ImageMagick/blob/7.1.2-31/MagickCore/policy.c#L1138-L1145","label":"disclosure@vulncheck.com"},{"url":"https://github.com/ImageMagick/ImageMagick/commit/1926ccf119141c26274c120d1899dffae19b0c71","label":"disclosure@vulncheck.com"},{"url":"https://github.com/ImageMagick/ImageMagick/commit/399d4bd3b081f44c7fef78153f65e8cdebed9f1a","label":"disclosure@vulncheck.com"},{"url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-jjp4-3fwf-393j","label":"disclosure@vulncheck.com"},{"url":"https://github.com/ImageMagick/ImageMagick6/commit/402ebc5353e569234908962cbdf451531ff66a57","label":"disclosure@vulncheck.com"},{"url":"https://github.com/ImageMagick/ImageMagick6/commit/da6022b2efe6cce8a2fd8f9e51188a45a3b9d558","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-32-and-6.9.13-57-security-policy-bypass-via-policy-xml-doctype","label":"disclosure@vulncheck.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-105083.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-105083"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2545467"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-105083"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105083"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ingestedAt":"2026-10-03T02:37:32.154Z","slug":"CVE-2026-105083","body":"## Overview\n\nImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when policy.xml uses an alternate DOCTYPE. A valid DOCTYPE not ending in ']>' makes the parser consume the rest of the file, so no policy rules are applied and restricted operations become allowed.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Low · affected: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7 · updated 2026-10-03 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-105083.json)","depth":"sunlit","depthScore":21,"depthScoreParts":{"impact":21.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}