CVE-2026-25985: Memory allocation with excessive without limits in the internal SVG decoder

Published Feb 24, 2026
·
Updated

A crafted SVG file containing an malicious element causes ImageMagick to attempt to allocate ~674 GB of memory, leading to an out-of-memory abort.

Found via AFL++ fuzzing with afl-clang-lto instrumentation and AddressSanitizer.

Other sources

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted SVG file containing an malicious element causes ImageMagick to attempt to allocate ~674 GB of memory, leading to an out-of-memory abort. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

MITRE

Affected Software

21 affected componentsFixes available
ImageMagick ImageMagick<7.1.2-15
ImageMagick ImageMagick<6.9.13-40
nuget/Magick.NET-Q8-x86<14.10.3
14.10.3
nuget/Magick.NET-Q8-arm64<14.10.3
14.10.3
nuget/Magick.NET-Q8-OpenMP-x64<14.10.3
14.10.3
nuget/Magick.NET-Q8-OpenMP-arm64<14.10.3
14.10.3
nuget/Magick.NET-Q8-AnyCPU<14.10.3
14.10.3
nuget/Magick.NET-Q16-x86<14.10.3
14.10.3
nuget/Magick.NET-Q16-arm64<14.10.3
14.10.3
nuget/Magick.NET-Q16-OpenMP-x86<14.10.3
14.10.3
nuget/Magick.NET-Q16-OpenMP-x64<14.10.3
14.10.3
nuget/Magick.NET-Q16-OpenMP-arm64<14.10.3
14.10.3
nuget/Magick.NET-Q16-HDRI-x86<14.10.3
14.10.3
nuget/Magick.NET-Q16-HDRI-x64<14.10.3
14.10.3
nuget/Magick.NET-Q16-HDRI-arm64<14.10.3
14.10.3
nuget/Magick.NET-Q16-HDRI-OpenMP-x64<14.10.3
14.10.3
nuget/Magick.NET-Q16-HDRI-OpenMP-arm64<14.10.3
14.10.3
nuget/Magick.NET-Q16-HDRI-AnyCPU<14.10.3
14.10.3
nuget/Magick.NET-Q16-AnyCPU<14.10.3
14.10.3
ImageMagick ImageMagick<6.9.13-40
ImageMagick ImageMagick>=7.0.0-0<7.1.2-15

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade nuget/Magick.NET-Q8-x86 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  2. Upgrade

    Upgrade nuget/Magick.NET-Q8-x64 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  3. Upgrade

    Upgrade nuget/Magick.NET-Q8-arm64 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  4. Upgrade

    Upgrade nuget/Magick.NET-Q8-OpenMP-x64 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  5. Upgrade

    Upgrade nuget/Magick.NET-Q8-OpenMP-arm64 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  6. Upgrade

    Upgrade nuget/Magick.NET-Q8-AnyCPU to a version that resolves this vulnerability.

    Fixed in 14.10.3
  7. Upgrade

    Upgrade nuget/Magick.NET-Q16-x86 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  8. Upgrade

    Upgrade nuget/Magick.NET-Q16-x64 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  9. Upgrade

    Upgrade nuget/Magick.NET-Q16-arm64 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  10. Upgrade

    Upgrade nuget/Magick.NET-Q16-OpenMP-x86 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  11. Upgrade

    Upgrade nuget/Magick.NET-Q16-OpenMP-x64 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  12. Upgrade

    Upgrade nuget/Magick.NET-Q16-OpenMP-arm64 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  13. Upgrade

    Upgrade nuget/Magick.NET-Q16-HDRI-x86 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  14. Upgrade

    Upgrade nuget/Magick.NET-Q16-HDRI-x64 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  15. Upgrade

    Upgrade nuget/Magick.NET-Q16-HDRI-arm64 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  16. Upgrade

    Upgrade nuget/Magick.NET-Q16-HDRI-OpenMP-x64 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  17. Upgrade

    Upgrade nuget/Magick.NET-Q16-HDRI-OpenMP-arm64 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  18. Upgrade

    Upgrade nuget/Magick.NET-Q16-HDRI-AnyCPU to a version that resolves this vulnerability.

    Fixed in 14.10.3
  19. Upgrade

    Upgrade nuget/Magick.NET-Q16-AnyCPU to a version that resolves this vulnerability.

    Fixed in 14.10.3
  20. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 7.1.2-15
  21. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 6.9.13-40

Event History

Feb 24, 2026
CVE Published
via MITRE·01:43 AM
Data Sourced
via MITRE·01:43 AM
DescriptionSeverityWeakness
Data Sourced
via Red Hat·02:03 AM
DescriptionSeverityAffected Software
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·03:44 PM
Data Sourced
via GitHub·03:44 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-25985?

CVE-2026-25985 has been classified as a high severity vulnerability due to potential memory allocation issues that can be exploited.

2

How do I fix CVE-2026-25985?

To fix CVE-2026-25985, upgrade to ImageMagick version 7.1.2-15 or 6.9.13-40 and later.

3

What types of systems are affected by CVE-2026-25985?

CVE-2026-25985 affects all versions of ImageMagick prior to 7.1.2-15 and 6.9.13-40.

4

What impact does CVE-2026-25985 have on applications using ImageMagick?

CVE-2026-25985 may allow an attacker to create a crafted SVG file that could cause excessive memory allocation, leading to potential denial of service.

5

Is CVE-2026-25985 exploitable in all scenarios?

While CVE-2026-25985 has potential exploitability, the actual risk may vary based on specific application configurations and usage patterns.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203