
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-86420 is a denial-of-service vulnerability in ImageMagick caused by improper memory budget management in the OpenPixelCache function. When an operation inside OpenPixelCache fails, the memory budget is not correctly lowered, allowing repeated triggering of such failures to exhaust the process memory budget and crash or hang the process. It affects ImageMagick versions before 7.1.2-30 (7.x branch) and before 6.9.13-55 (6.x branch). The vulnerability was published on September 7, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 7.5 (High) per NVD, though the upstream advisory rates it as Low (3.7) with CVSS v3.1 and Moderate (6.3) with CVSS v4.0 (GitHub Advisory, Feedly).
The root cause is classified as CWE-400 (Uncontrolled Resource Consumption) and CWE-772/CWE-401 (Missing Release of Memory after Effective Lifetime). When OpenPixelCache encounters a failure mid-operation, the code path responsible for reducing the allocated memory budget is not executed, leaving the budget inflated. An unauthenticated remote attacker can repeatedly submit image processing requests that trigger these failures, causing cumulative memory exhaustion without requiring any privileges or user interaction. The attack requires specific conditions to be present (Attack Requirements: Present in CVSS v4.0), adding some complexity to reliable exploitation (GitHub Advisory, Feedly).
Successful exploitation results in a denial-of-service condition affecting the availability of the ImageMagick process, which may become unresponsive or crash entirely. There is no impact on confidentiality or integrity — the vulnerability is purely an availability issue. Applications and services that rely on ImageMagick for image processing (e.g., web applications accepting user-uploaded images) are at risk of service disruption if an attacker can repeatedly trigger the vulnerable code path (GitHub Advisory, Red Hat Bugzilla).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.27–0.32%, indicating a low near-term exploitation probability. NVD's SSVC assessment also classifies exploitation as "none" currently (Feedly, GitHub Advisory).
OpenPixelCache; high-frequency image processing requests from a single source IP.Upgrade ImageMagick to version 7.1.2-30 or later (7.x branch) or 6.9.13-55 or later (6.x branch) to apply the official patch (GitHub Advisory). If immediate patching is not feasible, implement rate limiting on image processing endpoints to reduce the ability of an attacker to repeatedly trigger failures, and monitor ImageMagick process memory usage for unexpected spikes. Restricting the types and sizes of accepted image files can also reduce the attack surface (Feedly).
The vulnerability was reported by researcher Yanhaoxi and published by ImageMagick maintainer dlemstra via the official GitHub Security Advisory. Red Hat has tracked the issue via Bugzilla (Bug 2529441) with a low severity rating. No significant broader media coverage or notable community discussion has been observed beyond standard vulnerability database entries (GitHub Advisory, Red Hat Bugzilla).
Fix availability across major Linux distributions and their releases.
bookworm
imagemagick
sid
imagemagick: 8:7.1.2.31+dfsg1-1
trixie
imagemagick
bionic (esm-infra)
imagemagick
devel
imagemagick
focal (esm-apps)
imagemagick
jammy
imagemagick
jammy (esm-apps)
imagemagick
noble
imagemagick
noble (esm-apps)
imagemagick
resolute
imagemagick
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."