CVE-2026-86421: ImageMagick before 7.1.2-30 Memory Leak via MSL decoder
ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service.
Affected Software
Event History
Frequently Asked Questions
Which ImageMagick releases are affected?
ImageMagick releases before 7.1.2-30 and before 6.9.13-55 are affected. Upgrade to the stated fixed release or a later release in the applicable branch.
What must an attacker do to trigger the issue?
An attacker must cause ImageMagick to process a crafted MSL image. The issue can exhaust memory and cause a denial of service; no confidentiality or integrity impact is identified.
Which deployments are most exposed?
Deployments that use ImageMagick to process MSL images supplied through a network-accessible workflow are exposed to attempted exploitation. The provided data indicates no authentication or user interaction is required.