
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-53467 is a heap information disclosure vulnerability in the ImageMagick MNG (Multiple-image Network Graphics) decoder. Prior to fixed versions, the decoder leaves portions of allocated heap memory unchanged during pixel processing, allowing sensitive memory contents to be exposed through the decoded image output. The vulnerability affects all ImageMagick versions before 6.9.13-51 (legacy branch) and versions 7.0.1-0 through before 7.1.2-26 (current branch). It was published on July 1, 2026, with the fix credited to researcher Serotav. The CVSS v3.1 base score is 5.3 (Medium) (GitHub Advisory, Red Hat Bugzilla).
The root cause is classified under CWE-908 (Use of Uninitialized Resource) and CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). During MNG image decoding, the ImageMagick MNG decoder allocates heap memory for pixel data but fails to fully initialize or overwrite all allocated pixel regions, leaving residual heap contents embedded in the output image. An unauthenticated remote attacker can supply a crafted MNG file to any application that processes images via ImageMagick, causing the decoder to return an output image containing fragments of uninitialized heap memory that may include sensitive process data (GitHub Advisory, Red Hat Bugzilla). No public proof-of-concept exploit code has been identified (Feedly).
Successful exploitation results in partial disclosure of heap memory contents from the ImageMagick process, potentially exposing sensitive data such as cryptographic material, credentials, or other in-memory secrets embedded in the output image. There is no impact on integrity or availability. The vulnerability is network-exploitable without authentication or user interaction, making it automatable against any service that accepts and processes user-supplied MNG images using a vulnerable ImageMagick version (GitHub Advisory, Feedly).
Upgrade ImageMagick to version 6.9.13-51 or later (legacy branch) or 7.1.2-26 or later (current branch), which contain the fix for this vulnerability (GitHub Advisory). If immediate patching is not feasible, restrict or disable MNG image format processing in your ImageMagick policy configuration (e.g., by setting <policy domain="coder" rights="none" pattern="MNG" /> in policy.xml). Linux distribution users should apply vendor-provided security updates from Red Hat, SUSE, Debian, or openSUSE as they become available (Red Hat Bugzilla, Feedly).
The vulnerability was reported by researcher Serotav and disclosed via the ImageMagick GitHub Security Advisory program. Red Hat has tracked the issue via Bugzilla and assigned medium severity. SUSE and openSUSE have issued security update announcements for their distributions. No significant broader media coverage or notable social media discussion has been identified beyond standard security advisory channels (GitHub Advisory, Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."