
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-64685 is a heap buffer over-read vulnerability in the BGR decoder of ImageMagick, a widely used open-source image editing library. The flaw arises because the BGR decoder fails to check for end-of-file conditions in every location, allowing a crafted image file to trigger an out-of-bounds memory read. It affects all ImageMagick versions prior to 7.1.2-27 (and prior to 6.9.13-55 in the 6.x branch), and was disclosed on July 29–30, 2026. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-125 (Out-of-bounds Read): the BGR image decoder in ImageMagick does not validate end-of-file conditions at every read location during image parsing. An attacker can supply a specially crafted BGR image file that causes the decoder to read beyond the allocated heap buffer, potentially exposing adjacent memory contents. No authentication or user interaction is required, and the attack can be delivered remotely by submitting a malicious image to any service that processes BGR images via ImageMagick. The vulnerability was reported by researcher kongzhenhit-code and fixed in the upstream repository (GitHub Advisory).
Successful exploitation results in an information disclosure (memory disclosure) condition, where an attacker can read sensitive data from adjacent heap memory of the ImageMagick process. There is no impact on integrity or availability. In environments where ImageMagick processes user-supplied images (e.g., web applications, media pipelines), heap memory contents — which may include credentials, tokens, or other sensitive data — could be exposed to an unauthenticated remote attacker (GitHub Advisory, Red Hat Bugzilla).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability is automatable (no user interaction required) and exploitable by unauthenticated remote attackers, which increases its attractiveness as a target. The EPSS score is approximately 0.197%, indicating a low but non-negligible probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
coders/bgr.c or BGR decoder in ImageMagick debug output.convert, magick) consuming unexpected amounts of memory or crashing when processing specific image files; child processes spawned with unusual image file arguments..bgr or raw image files in upload directories or temporary processing folders.The fix is available in ImageMagick version 7.1.2-27 and 6.9.13-55; upgrading to these or later versions is the recommended remediation (GitHub Advisory). SUSE has released security updates (SUSE-SU-2026:3571-1 and SUSE-SU-2026:3586-1) addressing this vulnerability for affected distributions (SUSE Advisory). If immediate patching is not feasible, restrict or disable processing of untrusted BGR image files, or disable the BGR decoder if it is not required in your environment. Additionally, sandboxing ImageMagick processes can limit the impact of a successful heap over-read.
SUSE issued security advisories (SUSE-SU-2026:3571-1 and SUSE-SU-2026:3586-1) and openSUSE published security announcements addressing this vulnerability (SUSE Advisory). AusCERT published bulletins (ESB-2026.9386 and ESB-2026.9406) to notify its constituency. Coverage has been limited to standard vulnerability tracking and distribution-level patch announcements, with no notable researcher commentary or significant social media discussion observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."