CVE-2026-107208: ImageMagick: Denial of service with crafted XMP profile
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, a crafted XMP profile can reach a recursion limit that is handled as a fatal condition instead of an ordinary exception, terminating the image-processing process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 7.1.2-30 - Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 6.9.13-55
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems that process images with affected ImageMagick versions are exposed when they handle an image containing a crafted XMP profile. The provided vector indicates the attack can be performed remotely without authentication or user interaction.
What does successful exploitation do?
A crafted XMP profile can cause ImageMagick to treat a recursion-limit condition as fatal, terminating the image-processing process. The stated impact is denial of service; no confidentiality or integrity impact is indicated.
Which versions contain the fix?
The issue is fixed in ImageMagick 7.1.2-30 and 6.9.13-55. Versions prior to those releases are affected.