CVE-2026-105401: ImageMagick before 7.1.2-31 Heap Buffer Overflow in Distributed Pixel Cache Server
Rejected reason: This CVE ID has been rejected as a duplicate.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments running an affected ImageMagick version with the distributed pixel cache server reachable by connecting clients are exposed. The described impact is a server crash and denial of service.
What does an attacker need to exploit it?
An attacker needs network access to connect to the distributed pixel cache server. No privileges or user interaction are required, but exploitation requires crafted data and has high attack complexity.
What should be done if immediate patching is not possible?
Restrict access to the distributed pixel cache server so untrusted clients cannot connect to it. This reduces exposure because the attack requires a client connection to the server.
How can I determine whether I am affected?
Check whether ImageMagick is running a version before 7.1.2-31 and whether the distributed pixel cache server accepts client connections. Systems meeting both conditions are affected by the described vulnerability.