CVE-2026-105825: ImageMagick before 7.1.2-30 Denial of Service via Crafted XMP Profile
ImageMagick before 6.9.13-55 and 7.x before 7.1.2-30 contains a denial of service vulnerability in its handling of XMP profiles, where a crafted profile terminates the process instead of raising an exception. Attackers can supply images with malicious XMP profiles to crash applications that process them using ImageMagick.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
Applications using ImageMagick versions before 6.9.13-55, or 7.x versions before 7.1.2-30, are affected when they process images containing XMP profiles.
What does an attacker need to exploit this issue?
An attacker only needs to provide a crafted image with a malicious XMP profile to an application that processes the image with a vulnerable ImageMagick version. No privileges or user interaction are required.
What is the practical impact?
Processing the crafted image can terminate the affected process, causing a denial of service. The provided information indicates no confidentiality or integrity impact.
How can the issue be remediated?
Upgrade ImageMagick to 6.9.13-55 or later in the 6.x line, or to 7.1.2-30 or later in the 7.x line.