6.2
CVE-2026-106579
- EPSS -
- Veröffentlicht 07.10.2026 15:45:06
- Zuletzt bearbeitet 07.10.2026 18:17:17
- Erkennungen
ImageMagick: Policy Bypass when using coder as the domain.
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can bypass an ImageMagick security policy that uses coder as its domain, potentially allowing data prohibited by the policy to be read. This issue is fixed in versions 7.1.2-31 and 6.9.13-56.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerImageMagick
≫
Produkt
ImageMagick
Version
< 6.9.13-56
Status
affected
Version
>= 7.0.0, < 7.1.2-31
Status
affected
VulnDex Vulnerability Enrichment
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 6.2 | 2.5 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-551 Incorrect Behavior Order: Authorization Before Parsing and Canonicalization
If a web server does not fully parse requested URLs before it examines them for authorization, it may be possible for an attacker to bypass authorization protection.
https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31
https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-vcjj-32hg-qpx5
https://github.com/ImageMagick/ImageMagick/commit/82f373fedb3425c83a239103ab86f4fa86fd49ac
https://github.com/ImageMagick/ImageMagick/commit/dcdbbf4278fab20a32a4ad80e64cb95c368ca8dd
https://github.com/ImageMagick/ImageMagick6/commit/ac85c8e0a319b1eaf4c3d05d326605f5bae723d6
https://github.com/ImageMagick/ImageMagick6/commit/c54667bfe605ebdc17c23cb70a26dbe00b338222