CVE-2026-106569: ImageMagick: Denial of service in ASE decoder because of missing security checks
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, missing validation and resource checks in the ASE decoder allow a crafted ASE image to cause a crash or a long-running operation. This issue is fixed in version 7.1.2-32.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 7.1.2-32
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments using ImageMagick versions before 7.1.2-32 are affected when they process ASE image files. An unauthenticated attacker can trigger the issue over the network where they can submit or otherwise cause processing of a crafted ASE image.
What is the impact of successful exploitation?
A crafted ASE image can cause ImageMagick to crash or enter a long-running operation, resulting in denial of service. The provided severity vector indicates no confidentiality or integrity impact.
Is user interaction or prior access required?
No. The supplied vector indicates network attackability, low attack complexity, no privileges required, and no user interaction required; the attacker needs a path for a crafted ASE image to be decoded.
How should this be remediated?
Upgrade ImageMagick to version 7.1.2-32, which fixes the missing validation and resource checks in the ASE decoder.