---
id: CVE-2026-93590
title: >-
  ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR
  encoder that fails to perform policy checks during buffer allocation for image
  pixels
summary: >-
  ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR
  encoder that fails to perform policy checks during buffer allocation for image
  pixels. Attackers can bypass resource policies by processing specially crafted
  …
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-400
vendor: ImageMagick
product: ImageMagick
affected:
  - ImageMagick < 7.1.2-31
published: '2026-09-18'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T20:25:55.870'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93590'
references:
  - url: >-
      https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7hjx-392p-f8cm
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-31-policy-bypass-in-uhdr-encoder
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.00312
epssPercentile: 0.24271
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-21T16:22:45.986868Z'
ingestedAt: '2026-09-18T13:41:41.666Z'
---

## Overview

ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer allocation for image pixels. Attackers can bypass resource policies by processing specially crafted UHDR images, potentially causing denial of service through excessive memory allocation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
