CVE-2026-86425
ImageMagick vulnerability analysis and mitigation

Overview

CVE-2026-86425 is a heap-use-after-free vulnerability in the Layer method of PerlMagick (ImageMagick's Perl interface). An attacker who supplies a crafted list of images can trigger memory access after deallocation, resulting in an application crash (denial of service). It affects ImageMagick versions before 7.1.2-30 and 6.9.x versions before 6.9.13-55. The vulnerability was published on September 7, 2026, with a CVSS v3.1 base score of 3.3 (Low) and a CVSS v4.0 base score of 4.8 (Medium) (GitHub Advisory, ImageMagick Advisory).

Technical details

The root cause is a CWE-416 (Use After Free) flaw in the Layer method of PerlMagick, where memory is accessed after it has been freed during the processing of an image list. When a crafted sequence of images is passed to the Layer method, the internal memory management fails to properly track object lifetimes, allowing a dangling pointer dereference that triggers a crash. Exploitation requires local access and user interaction — specifically, a user or process must invoke the vulnerable Layer method with attacker-controlled image input. The vulnerability was reported by researcher mangowithegg (ImageMagick Advisory).

Impact

Successful exploitation results in a denial of service through an application crash, with no impact on confidentiality or data integrity. The scope is limited to the availability of the ImageMagick/PerlMagick process itself; there is no evidence of potential for code execution, privilege escalation, or lateral movement based on current analysis. The impact is confined to local environments where PerlMagick's Layer method processes untrusted image input (GitHub Advisory, ImageMagick Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is 0.0, reflecting a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access and user interaction, significantly limiting the attacker's opportunity (GitHub Advisory, Feedly).

Mitigation and workarounds

Upgrade ImageMagick to version 7.1.2-30 or later, or to 6.9.13-55 or later for the 6.9.x branch, where the vulnerability has been patched. If immediate patching is not feasible, restrict access to the PerlMagick Layer method functionality and implement input validation to prevent processing of untrusted or malformed image lists. Avoid exposing ImageMagick/PerlMagick image processing pipelines to untrusted user-supplied input until the patch is applied (ImageMagick Advisory, GitHub Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

imagemagick

Affected

sid

imagemagick: 8:7.1.2.31+dfsg1-1

Fixed

trixie

imagemagick

Affected

Ubuntu

Unknown

bionic (esm-infra)

imagemagick

Unknown

devel

imagemagick

Unknown

focal (esm-apps)

imagemagick

Unknown

jammy

imagemagick

Unknown

jammy (esm-apps)

imagemagick

Unknown

noble

imagemagick

Unknown

noble (esm-apps)

imagemagick

Unknown

resolute

imagemagick

Unknown

RHEL / CentOS

Unknown

Alpine

Affected

edge

7.0.8.38-r0

Affected

v3.24

7.1.2.24-r0

Affected

SourceThis report was generated using AI

Related ImageMagick vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86421MEDIUM6.3
  • ImageMagick logoImageMagick
  • ImageMagick-c++
NoYesSep 07, 2026
CVE-2026-86425MEDIUM4.8
  • ImageMagick logoImageMagick
  • seal-ImageMagick
NoYesSep 07, 2026
CVE-2026-86423MEDIUM4.8
  • ImageMagick logoImageMagick
  • ImageMagick-c++
NoYesSep 07, 2026
CVE-2026-86424LOW2
  • ImageMagick logoImageMagick
  • imagemagick
NoYesSep 07, 2026
CVE-2026-86422LOW1
  • ImageMagick logoImageMagick
  • cpe:2.3:a:imagemagick:imagemagick
NoYesSep 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management