Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-86420
ImageMagick vulnerability analysis and mitigation

Overview

CVE-2026-86420 is a denial-of-service vulnerability in ImageMagick caused by improper memory budget management in the OpenPixelCache function. When an operation inside OpenPixelCache fails, the memory budget is not correctly lowered, allowing repeated triggering of such failures to exhaust the process memory budget and crash or hang the process. It affects ImageMagick versions before 7.1.2-30 (7.x branch) and before 6.9.13-55 (6.x branch). The vulnerability was published on September 7, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 7.5 (High) per NVD, though the upstream advisory rates it as Low (3.7) with CVSS v3.1 and Moderate (6.3) with CVSS v4.0 (GitHub Advisory, Feedly).

Technical details

The root cause is classified as CWE-400 (Uncontrolled Resource Consumption) and CWE-772/CWE-401 (Missing Release of Memory after Effective Lifetime). When OpenPixelCache encounters a failure mid-operation, the code path responsible for reducing the allocated memory budget is not executed, leaving the budget inflated. An unauthenticated remote attacker can repeatedly submit image processing requests that trigger these failures, causing cumulative memory exhaustion without requiring any privileges or user interaction. The attack requires specific conditions to be present (Attack Requirements: Present in CVSS v4.0), adding some complexity to reliable exploitation (GitHub Advisory, Feedly).

Impact

Successful exploitation results in a denial-of-service condition affecting the availability of the ImageMagick process, which may become unresponsive or crash entirely. There is no impact on confidentiality or integrity — the vulnerability is purely an availability issue. Applications and services that rely on ImageMagick for image processing (e.g., web applications accepting user-uploaded images) are at risk of service disruption if an attacker can repeatedly trigger the vulnerable code path (GitHub Advisory, Red Hat Bugzilla).

Exploitability

No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.27–0.32%, indicating a low near-term exploitation probability. NVD's SSVC assessment also classifies exploitation as "none" currently (Feedly, GitHub Advisory).

Indicators of compromise

  • Process Behavior: ImageMagick processes consuming abnormally high or continuously growing memory without releasing it; processes becoming unresponsive or crashing repeatedly.
  • Logs: Application logs showing repeated image processing failures or errors originating from OpenPixelCache; high-frequency image processing requests from a single source IP.
  • Network: Unusual volume of image upload or processing requests from a single client, particularly with malformed or crafted image files designed to trigger processing failures.

Mitigation and workarounds

Upgrade ImageMagick to version 7.1.2-30 or later (7.x branch) or 6.9.13-55 or later (6.x branch) to apply the official patch (GitHub Advisory). If immediate patching is not feasible, implement rate limiting on image processing endpoints to reduce the ability of an attacker to repeatedly trigger failures, and monitor ImageMagick process memory usage for unexpected spikes. Restricting the types and sizes of accepted image files can also reduce the attack surface (Feedly).

Community reactions

The vulnerability was reported by researcher Yanhaoxi and published by ImageMagick maintainer dlemstra via the official GitHub Security Advisory. Red Hat has tracked the issue via Bugzilla (Bug 2529441) with a low severity rating. No significant broader media coverage or notable community discussion has been observed beyond standard vulnerability database entries (GitHub Advisory, Red Hat Bugzilla).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

imagemagick

Affected

sid

imagemagick: 8:7.1.2.31+dfsg1-1

Fixed

trixie

imagemagick

Affected

Ubuntu

Unknown

bionic (esm-infra)

imagemagick

Unknown

devel

imagemagick

Unknown

focal (esm-apps)

imagemagick

Unknown

jammy

imagemagick

Unknown

jammy (esm-apps)

imagemagick

Unknown

noble

imagemagick

Unknown

noble (esm-apps)

imagemagick

Unknown

resolute

imagemagick

Unknown

RHEL / CentOS

Unknown

Alpine

Affected

edge

7.0.8.38-r0

Affected

v3.24

7.1.2.24-r0

Affected

SourceThis report was generated using AI

Related ImageMagick vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93590MEDIUM6.3
  • ImageMagick logoImageMagick
  • cpe:2.3:a:imagemagick:imagemagick
NoYesSep 18, 2026
CVE-2026-93589MEDIUM6.3
  • ImageMagick logoImageMagick
  • cpe:2.3:a:imagemagick:imagemagick
NoYesSep 18, 2026
CVE-2026-93587MEDIUM4.8
  • ImageMagick logoImageMagick
  • imagemagick
NoYesSep 18, 2026
CVE-2026-93588LOW2.3
  • ImageMagick logoImageMagick
  • cpe:2.3:a:imagemagick:imagemagick
NoYesSep 18, 2026
CVE-2026-93586LOW2.1
  • ImageMagick logoImageMagick
  • cpe:2.3:a:imagemagick:imagemagick
NoYesSep 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management