CVE-2026-105405: ImageMagick before 7.1.2-31 Invalid Memory Free in MVG Decoder
Published Oct 8, 2026
·Updated
Rejected reason: This CVE ID has been rejected as a duplicate.
Affected Software
1 affected component
ImageMagick ImageMagick<6.9.13-56, <7.1.2-31
Event History
Oct 8, 2026
CVE Published
via MITRE·02:10 PM
Rejected
via MITRE·02:10 PM
Data Sourced
via NVD·03:17 PM
Description
Oct 9, 2026
Rejected
via MITRE·01:03 PM
Frequently Asked Questions
1
Which deployments are exposed to this issue?
Deployments using ImageMagick versions earlier than 6.9.13-56, or 7.x versions earlier than 7.1.2-31, are affected when they process MVG images.
2
What does an attacker need to exploit the vulnerability?
An attacker needs to supply a crafted MVG image to an application or service that processes it with an affected ImageMagick version. No privileges or user interaction are required according to the supplied vector.
3
What is the practical impact of successful exploitation?
Successful exploitation can crash the application processing the crafted image, resulting in a denial of service. The provided data does not indicate confidentiality or integrity impact.