Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-93588
ImageMagick vulnerability analysis and mitigation

Overview

CVE-2026-93588 is a NULL pointer dereference vulnerability in the PNM coder of ImageMagick that can lead to a denial of service (application crash). It affects ImageMagick versions before 7.1.2-31 (7.x branch) and before 6.9.13-56 (6.9.x branch). The vulnerability was published on September 18, 2026, with the underlying security advisory (GHSA-92rw-c5mw-27v4) credited to reporter Yanhaoxi and published by maintainer dlemstra on September 3, 2026. It carries a CVSS v3.1 base score of 3.1 (Low) and a CVSS v4.0 base score of 2.3 (Low) (GitHub Advisory, ImageMagick Advisory).

Technical details

The root cause is classified as CWE-476 (NULL Pointer Dereference) and CWE-755 (Improper Handling of Exceptional Conditions). When the ImageMagick PNM coder encounters a memory (resource) limit at a specific point during image processing, the failed memory allocation is not properly handled — the code proceeds to dereference the resulting NULL pointer rather than returning an error. Exploitation requires an authenticated attacker with low privileges to supply a specially crafted or sufficiently large PNM image file for processing, either locally or over a network, and also depends on specific deployment conditions (attack requirements: present) (ImageMagick Advisory, GitHub Advisory).

Impact

Successful exploitation results in an application crash (denial of service), causing ImageMagick to become unavailable for image processing tasks. There is no impact to confidentiality or data integrity — the vulnerability is limited to availability of the affected ImageMagick process. The impact is scoped to the vulnerable system itself, with no lateral movement potential or data exposure risk identified (GitHub Advisory, ImageMagick Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires low privileges and specific attack conditions (high complexity, attack requirements present), further limiting practical exploitability (GitHub Advisory, ImageMagick Advisory).

Mitigation and workarounds

Upgrade ImageMagick to version 7.1.2-31 or later (7.x branch) or to version 6.9.13-56 or later (6.9.x branch) to remediate this vulnerability. As interim mitigations, administrators should enforce strict memory and resource limits in ImageMagick's policy configuration (policy.xml) to reduce the likelihood of triggering the vulnerable code path, and restrict which users or services are permitted to submit PNM image files for processing. Input validation to reject excessively large or malformed PNM files before they reach ImageMagick is also recommended (ImageMagick Advisory, GitHub Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

imagemagick

Affected

sid

imagemagick: 8:7.1.2.31+dfsg1-1

Fixed

trixie

imagemagick

Affected

SourceThis report was generated using AI

Related ImageMagick vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93590MEDIUM6.3
  • ImageMagick logoImageMagick
  • cpe:2.3:a:imagemagick:imagemagick
NoYesSep 18, 2026
CVE-2026-93589MEDIUM6.3
  • ImageMagick logoImageMagick
  • cpe:2.3:a:imagemagick:imagemagick
NoYesSep 18, 2026
CVE-2026-93587MEDIUM4.8
  • ImageMagick logoImageMagick
  • imagemagick
NoYesSep 18, 2026
CVE-2026-93588LOW2.3
  • ImageMagick logoImageMagick
  • cpe:2.3:a:imagemagick:imagemagick
NoYesSep 18, 2026
CVE-2026-93586LOW2.1
  • ImageMagick logoImageMagick
  • cpe:2.3:a:imagemagick:imagemagick
NoYesSep 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management