CVE-2026-86425: ImageMagick before 7.1.2-30 Heap-use-after-free via Layer
ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the Layer method of PerlMagick. An attacker who supplies a crafted list of images can trigger memory access after deallocation, resulting in a crash (denial of service).
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
The issue affects PerlMagick installations using ImageMagick releases before 7.1.2-30, or 6.9.x releases before 6.9.13-55. Deployments that do not use PerlMagick's Layer method are not described as exposed by the available information.
What is required to trigger the issue?
An attacker must be able to supply a crafted list of images that is processed through the PerlMagick Layer method. The stated impact is a crash resulting in denial of service.
How can I remediate this vulnerability?
Upgrade ImageMagick to 7.1.2-30 or later, or, for the 6.9.x branch, to 6.9.13-55 or later.