CVE-2026-105398Medium· 5.1▾ SunlitImageMagick before 7.1.2-31 contains a heap buffer overflow vulnerability that allows attackers to overwrite heap memory by making a crafted call to the GetVirtualPixels API. Attackers can trigger the out-of-bounds heap write through cra…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 28.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
ImageMagick before 7.1.2-31 contains a heap buffer overflow vulnerability that allows attackers to overwrite heap memory by making a crafted call to the GetVirtualPixels API. Attackers can trigger the out-of-bounds heap write through crafted input to crash the server, causing a denial of service.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-106571Medium· 5.1ImageMagick is free and open-source software used for editing and manipulating digital images
CVE-2026-106574Medium· 5.3ImageMagick is free and open-source software used for editing and manipulating digital images
CVE-2026-23876High· 8.1ImageMagick is free and open-source software used for editing and manipulating digital images
CVE-2026-105402Medium· 5.3ImageMagick before 7.1.2-31 contains a denial of service vulnerability that allows attackers to disrupt processing by supplying a crafted XMP profile
CVE-2026-105399Medium· 5.3ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 contains a denial of service vulnerability in the MVG decoder caused by a missing limit check
CVE-2026-105401Medium· 5.3ImageMagick before 7.1.2-31 contains a heap buffer overflow vulnerability in the distributed pixel cache server that allows connecting clients to overwrite heap memory by sending crafted data