4

CVE-2026-106580

ImageMagick: Policy Bypass in CUT encoder

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a missing security-policy check in the CUT encoder allows a crafted local encoding operation to read data that policy should deny and can also cause a crash. This issue is fixed in versions 7.1.2-31 and 6.9.13-56.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerImageMagick
≫
Produkt ImageMagick
Version < 6.9.13-56
Status affected
Version >= 7.0.0, < 7.1.2-31
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 4 1.4 2.5
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31
https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-r868-pmwh-fv2c
https://github.com/ImageMagick/ImageMagick/commit/768bdd0dbb9a9ad743b6a6e557126b788b325970
https://github.com/ImageMagick/ImageMagick6/commit/ad178e41fce2afa6be2b91fb4e7f41c4c5448117