---
id: CVE-2026-105401
title: >-
  ImageMagick before 7.1.2-31 contains a heap buffer overflow vulnerability in
  the distributed pixel cache server that allows connecting clients to overwrite
  heap memory by sending crafted data
summary: >-
  ImageMagick before 7.1.2-31 contains a heap buffer overflow vulnerability in
  the distributed pixel cache server that allows connecting clients to overwrite
  heap memory by sending crafted data. Attackers can connect to the distributed
  pix…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-122
vendor: ImageMagick
product: ImageMagick
affected:
  - ImageMagick < 7.1.2-31
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T15:17:33.310'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105401'
references:
  - url: >-
      https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4fq9-vrx7-gv92
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-31-heap-buffer-overflow-in-distributed-pixel-cache-server
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-08T14:47:16.364Z'
---

## Overview

ImageMagick before 7.1.2-31 contains a heap buffer overflow vulnerability in the distributed pixel cache server that allows connecting clients to overwrite heap memory by sending crafted data. Attackers can connect to the distributed pixel cache server and transmit malicious data to trigger a heap buffer over-write that crashes the server, causing denial of service.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
