CVE-2026-105825Medium· 5.3▾ SunlitImageMagick before 6.9.13-55 and 7.x before 7.1.2-30 contains a denial of service vulnerability in its handling of XMP profiles, where a crafted profile terminates the process instead of raising an exception. Attackers can supply images …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
ImageMagick before 6.9.13-55 and 7.x before 7.1.2-30 contains a denial of service vulnerability in its handling of XMP profiles, where a crafted profile terminates the process instead of raising an exception. Attackers can supply images with malicious XMP profiles to crash applications that process them using ImageMagick.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-107208Medium· 5.3ImageMagick is free and open-source software used for editing and manipulating digital images
CVE-2026-105402Medium· 5.3ImageMagick before 7.1.2-31 contains a denial of service vulnerability that allows attackers to disrupt processing by supplying a crafted XMP profile
CVE-2026-105399Medium· 5.3ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 contains a denial of service vulnerability in the MVG decoder caused by a missing limit check
CVE-2026-106580Medium· 4.0ImageMagick is free and open-source software used for editing and manipulating digital images
CVE-2026-106576Medium· 5.3ImageMagick is free and open-source software used for editing and manipulating digital images
CVE-2026-106573Medium· 5.3ImageMagick is free and open-source software used for editing and manipulating digital images