Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-93586
ImageMagick vulnerability analysis and mitigation

Overview

CVE-2026-93586 is a use-after-free vulnerability in ImageMagick's ImagesToBlob method, caused by a pointer that is not updated correctly after memory is freed. It affects ImageMagick versions before 7.1.2-31 (7.x branch) and before 6.9.13-56 (6.x branch). The vulnerability was published on September 18, 2026, with the underlying security advisory (GHSA-3rjr-534c-8v67) published by maintainer dlemstra on September 3, 2026. It carries a CVSS v3.1 base score of 2.9 (Low) and a CVSS v4.0 base score of 2.1 (Low) (GitHub Advisory, ImageMagick Advisory).

Technical details

The root cause is classified as CWE-416 (Use After Free) and potentially CWE-415 (Double Free), where a pointer within the ImagesToBlob method is not updated correctly after the associated memory is freed, allowing subsequent access to freed memory (ImageMagick Advisory). The attack vector is local with high attack complexity, and specific deployment conditions (Attack Requirements: Present) must be met for exploitation — meaning the vulnerability is not trivially triggered in all configurations. No privileges are required and no user interaction is needed, but the high complexity and local-only access significantly limit practical exploitability (GitHub Advisory). The vulnerability was reported by researcher "Nosiume" (ImageMagick Advisory).

Impact

Successful exploitation results in a limited availability impact — specifically, a crash of the affected ImageMagick process — constituting a denial of service condition. There is no impact to confidentiality or integrity, and the scope is unchanged, meaning the vulnerability cannot be leveraged to affect other system components or enable lateral movement (GitHub Advisory, ImageMagick Advisory). Applications that rely on ImageMagick for image processing pipelines (e.g., web services converting or exporting image blobs) could experience service interruptions if an attacker can supply crafted input to trigger the vulnerable code path.

Exploitability

As of the publication date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is 0.0, reflecting a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The high attack complexity and local-only attack vector further reduce the likelihood of opportunistic exploitation.

Mitigation and workarounds

Update ImageMagick to version 7.1.2-31 or later (for the 7.x branch) or 6.9.13-56 or later (for the 6.x branch), which contain the fix for this vulnerability (ImageMagick Advisory). If immediate patching is not feasible, restrict local access to systems running vulnerable ImageMagick versions and limit exposure of the ImagesToBlob processing path to untrusted or user-supplied image inputs. Given the low severity and local-only attack vector, patching during the next regular maintenance cycle is generally acceptable for most environments.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

imagemagick

Affected

sid

imagemagick: 8:7.1.2.31+dfsg1-1

Fixed

trixie

imagemagick

Affected

SourceThis report was generated using AI

Related ImageMagick vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93590MEDIUM6.3
  • ImageMagick logoImageMagick
  • cpe:2.3:a:imagemagick:imagemagick
NoYesSep 18, 2026
CVE-2026-93589MEDIUM6.3
  • ImageMagick logoImageMagick
  • cpe:2.3:a:imagemagick:imagemagick
NoYesSep 18, 2026
CVE-2026-93587MEDIUM4.8
  • ImageMagick logoImageMagick
  • imagemagick
NoYesSep 18, 2026
CVE-2026-93588LOW2.3
  • ImageMagick logoImageMagick
  • cpe:2.3:a:imagemagick:imagemagick
NoYesSep 18, 2026
CVE-2026-93586LOW2.1
  • ImageMagick logoImageMagick
  • cpe:2.3:a:imagemagick:imagemagick
NoYesSep 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management