
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-93586 is a use-after-free vulnerability in ImageMagick's ImagesToBlob method, caused by a pointer that is not updated correctly after memory is freed. It affects ImageMagick versions before 7.1.2-31 (7.x branch) and before 6.9.13-56 (6.x branch). The vulnerability was published on September 18, 2026, with the underlying security advisory (GHSA-3rjr-534c-8v67) published by maintainer dlemstra on September 3, 2026. It carries a CVSS v3.1 base score of 2.9 (Low) and a CVSS v4.0 base score of 2.1 (Low) (GitHub Advisory, ImageMagick Advisory).
The root cause is classified as CWE-416 (Use After Free) and potentially CWE-415 (Double Free), where a pointer within the ImagesToBlob method is not updated correctly after the associated memory is freed, allowing subsequent access to freed memory (ImageMagick Advisory). The attack vector is local with high attack complexity, and specific deployment conditions (Attack Requirements: Present) must be met for exploitation — meaning the vulnerability is not trivially triggered in all configurations. No privileges are required and no user interaction is needed, but the high complexity and local-only access significantly limit practical exploitability (GitHub Advisory). The vulnerability was reported by researcher "Nosiume" (ImageMagick Advisory).
Successful exploitation results in a limited availability impact — specifically, a crash of the affected ImageMagick process — constituting a denial of service condition. There is no impact to confidentiality or integrity, and the scope is unchanged, meaning the vulnerability cannot be leveraged to affect other system components or enable lateral movement (GitHub Advisory, ImageMagick Advisory). Applications that rely on ImageMagick for image processing pipelines (e.g., web services converting or exporting image blobs) could experience service interruptions if an attacker can supply crafted input to trigger the vulnerable code path.
As of the publication date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is 0.0, reflecting a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The high attack complexity and local-only attack vector further reduce the likelihood of opportunistic exploitation.
Update ImageMagick to version 7.1.2-31 or later (for the 7.x branch) or 6.9.13-56 or later (for the 6.x branch), which contain the fix for this vulnerability (ImageMagick Advisory). If immediate patching is not feasible, restrict local access to systems running vulnerable ImageMagick versions and limit exposure of the ImagesToBlob processing path to untrusted or user-supplied image inputs. Given the low severity and local-only attack vector, patching during the next regular maintenance cycle is generally acceptable for most environments.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."