
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-86425 is a heap-use-after-free vulnerability in the Layer method of PerlMagick (ImageMagick's Perl interface). An attacker who supplies a crafted list of images can trigger memory access after deallocation, resulting in an application crash (denial of service). It affects ImageMagick versions before 7.1.2-30 and 6.9.x versions before 6.9.13-55. The vulnerability was published on September 7, 2026, with a CVSS v3.1 base score of 3.3 (Low) and a CVSS v4.0 base score of 4.8 (Medium) (GitHub Advisory, ImageMagick Advisory).
The root cause is a CWE-416 (Use After Free) flaw in the Layer method of PerlMagick, where memory is accessed after it has been freed during the processing of an image list. When a crafted sequence of images is passed to the Layer method, the internal memory management fails to properly track object lifetimes, allowing a dangling pointer dereference that triggers a crash. Exploitation requires local access and user interaction — specifically, a user or process must invoke the vulnerable Layer method with attacker-controlled image input. The vulnerability was reported by researcher mangowithegg (ImageMagick Advisory).
Successful exploitation results in a denial of service through an application crash, with no impact on confidentiality or data integrity. The scope is limited to the availability of the ImageMagick/PerlMagick process itself; there is no evidence of potential for code execution, privilege escalation, or lateral movement based on current analysis. The impact is confined to local environments where PerlMagick's Layer method processes untrusted image input (GitHub Advisory, ImageMagick Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is 0.0, reflecting a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access and user interaction, significantly limiting the attacker's opportunity (GitHub Advisory, Feedly).
Upgrade ImageMagick to version 7.1.2-30 or later, or to 6.9.13-55 or later for the 6.9.x branch, where the vulnerability has been patched. If immediate patching is not feasible, restrict access to the PerlMagick Layer method functionality and implement input validation to prevent processing of untrusted or malformed image lists. Avoid exposing ImageMagick/PerlMagick image processing pipelines to untrusted user-supplied input until the patch is applied (ImageMagick Advisory, GitHub Advisory).
Fix availability across major Linux distributions and their releases.
bookworm
imagemagick
sid
imagemagick: 8:7.1.2.31+dfsg1-1
trixie
imagemagick
bionic (esm-infra)
imagemagick
devel
imagemagick
focal (esm-apps)
imagemagick
jammy
imagemagick
jammy (esm-apps)
imagemagick
noble
imagemagick
noble (esm-apps)
imagemagick
resolute
imagemagick
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."