CVE-2026-105824 — ImageMagick before 6.9.13-55 and 7.x before 7.1.2-30 contains a use-after-free vulnerability in the RSVG decoder when built without cairo support, …
Description
ImageMagick before 6.9.13-55 and 7.x before 7.1.2-30 contains a use-after-free vulnerability in the RSVG decoder when built without cairo support, triggered when a limit is hit during decoding. Attackers can supply crafted SVG files that cause a limit to be reached, leading to access of freed memory and a crash.
CVSS v4.0 base metrics
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XHigh severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
High
Attack Complexity
AT
Present
Attack Requirements
PR
None
Privileges Required
UI
None
User Interaction
VC
None
Confidentiality (Vulnerable System)
VI
None
Integrity (Vulnerable System)
VA
High
Availability (Vulnerable System)
SC
None
Confidentiality (Subsequent System)
SI
None
Integrity (Subsequent System)
SA
None
Availability (Subsequent System)
References
Related threats
same CWE or vendorCVE-2026-14508 — IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a re…
CVE-2026-14508 · 9h ago
CVE-2026-107209 — ImageMagick is free and open-source software used for editing and manipulating digital images.
CVE-2026-107209 · 1d ago
CVE-2026-107167 — A flaw was found in m17n-lib.
CVE-2026-107167 · 1d ago
CVE-2026-107183 — llama.cpp before b11393 contains a use-after-free and double free vulnerability in common_chat_peg_mapper::map that allows unauthenticated remote a…
CVE-2026-107183 · 1d ago
CVE-2026-55330 — In BluetoothCccHandlerCallbackImpl of bluetooth_ccc.cc, there is a possible use-after-free due to a logic error in the code.
CVE-2026-55330 · 2d ago
CVE-2026-106423 — Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafte…
CVE-2026-106423 · 2d ago