Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

ImageMagick — Vulnerabilities & Security Advisories 98

Browse all 98 CVE security advisories affecting ImageMagick. AI-powered Chinese analysis, POCs, and references for each vulnerability.

ImageMagick is a widely used open-source software suite for creating, editing, and composing bitmap images, serving as a foundational backend for numerous web applications and content management systems. Its extensive feature set and default configuration have historically introduced significant security risks, resulting in nearly one hundred recorded Common Vulnerabilities and Exposures. The most prevalent issues involve Remote Code Execution (RCE) and Denial of Service (DoS), often triggered by maliciously crafted image files that exploit buffer overflows or unsafe command-line argument parsing. While Cross-Site Scripting (XSS) and privilege escalation vulnerabilities have also been documented, RCE remains the primary threat vector due to the tool’s ability to process complex image formats. Major incidents, such as the "ImageTragick" vulnerability, highlighted critical flaws in how the software handles input, prompting widespread adoption of stricter security policies and configuration hardening across the industry to mitigate these inherent risks.

Top products by ImageMagick: ImageMagick
MediumCVE-2019-101312026-04-18
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-f… · ImageMagick/ImageMagick@ccdc011 · GitHub
MediumCVE-2019-110422026-04-18
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-r… · ImageMagick/ImageMagick@5facfec · GitHub
HighCVE-2020-26472026-04-18
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-p… · ImageMagick/ImageMagick@3d653be · GitHub
HighGHSA-26qp-ffjh-2x4v2026-04-18
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-2… · ImageMagick/ImageMagick@bcd8519 · GitHub
Unknown2026-04-18
Release 7.1.2-19 · ImageMagick/ImageMagick · GitHub
MediumCVE-2026-259662026-02-24
Security Policy Bypass through config/policy-secure.xml via "fd handler" leads to stdin/stdout access · Advisory · Image
MediumCVE-2026-258982026-02-24
Global Buffer Overflow (OOB Read) via Negative Pixel Index in UIL and XPM Writer · Advisory · ImageMagick/ImageMagick ·
HighCVE-2026-259852026-02-24
Memory allocation with excessive without limits in the internal SVG decoder · Advisory · ImageMagick/ImageMagick · GitHu
MediumCVE-2026-256382026-02-24
Memory leak in msl encoder · Advisory · ImageMagick/ImageMagick · GitHub
MediumCVE-2026-256372026-02-24
Possible memory leak in ASHLAR encoder · Advisory · ImageMagick/ImageMagick · GitHub
MediumCVE-2026-257962026-02-24
Memory leak of watermark Image object in ReadSTEGANOImage on multiple error/early-return paths · Advisory · ImageMagick/
MediumCVE-2026-255762026-02-24
Out of bounds read in multiple coders that read raw pixel data · Advisory · ImageMagick/ImageMagick · GitHub
HighCVE-2026-244852026-02-24
An infinite loop vulnerability when parsing a PCD file · Advisory · ImageMagick/ImageMagick · GitHub
HighGHSA-39h3-g67r-7g3c2026-01-27
Release Magick.NET 14.10.2 · dlemstra/Magick.NET · GitHub
MediumCVE-2026-239522026-01-27
NULL pointer dereference in MSL parser via <comment> tag before image load · Advisory · ImageMagick/ImageMagick · GitHub
High2026-01-27
Heap buffer overflow with attacker-controlled data in XBM parser · Advisory · ImageMagick/ImageMagick · GitHub
MediumCVE-2025-659552025-12-04
[Security] Use-after-free/double-free risk in Options::fontFamily when clearing family · Advisory · ImageMagick/ImageMag
UnknownCVE-2017-117522025-11-14
Memory-Leak in in AcquireMagickMemory MagickCore/memory.c:464 · Issue #628 · ImageMagick/ImageMagick
HighDSA-4032-12025-11-12
[SECURITY] [DSA 4032-1] imagemagick security update
HighCVE-2018-164132025-11-12
heap-buffer-overflow bug in MagickCore/quantum-private.h: · Issue #1249 · ImageMagick/ImageMagick

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with ImageMagick. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.