6.2

CVE-2026-106579

ImageMagick: Policy Bypass when using coder as the domain.

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can bypass an ImageMagick security policy that uses coder as its domain, potentially allowing data prohibited by the policy to be read. This issue is fixed in versions 7.1.2-31 and 6.9.13-56.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerImageMagick
≫
Produkt ImageMagick
Version < 6.9.13-56
Status affected
Version >= 7.0.0, < 7.1.2-31
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 6.2 2.5 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-551 Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

If a web server does not fully parse requested URLs before it examines them for authorization, it may be possible for an attacker to bypass authorization protection.

https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31
https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-vcjj-32hg-qpx5
https://github.com/ImageMagick/ImageMagick/commit/82f373fedb3425c83a239103ab86f4fa86fd49ac
https://github.com/ImageMagick/ImageMagick/commit/dcdbbf4278fab20a32a4ad80e64cb95c368ca8dd
https://github.com/ImageMagick/ImageMagick6/commit/ac85c8e0a319b1eaf4c3d05d326605f5bae723d6
https://github.com/ImageMagick/ImageMagick6/commit/c54667bfe605ebdc17c23cb70a26dbe00b338222