CVE-2026-105824: ImageMagick before 7.1.2-30 Use-After-Free in RSVG Decoder Without Cairo
ImageMagick before 6.9.13-55 and 7.x before 7.1.2-30 contains a use-after-free vulnerability in the RSVG decoder when built without cairo support, triggered when a limit is hit during decoding. Attackers can supply crafted SVG files that cause a limit to be reached, leading to access of freed memory and a crash.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected by this issue?
Affected deployments use ImageMagick versions before 6.9.13-55 or 7.x before 7.1.2-30, have the RSVG decoder available, and were built without cairo support. The issue is reached when a decoding limit is hit.
What does an attacker need to exploit it?
An attacker needs to supply a crafted SVG file for ImageMagick to decode. The crafted input must cause a limit to be reached during RSVG decoding; no privileges or user interaction are required according to the provided vector.
What is the expected impact?
The described outcome is access to freed memory followed by a crash, resulting in denial of service. No confidentiality or integrity impact is indicated by the provided severity vector.