CVE-2026-107209 — ImageMagick is free and open-source software used for editing and manipulating digital images.
Description
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, when ImageMagick is built without Cairo support, a crafted RSVG image that reaches a resource limit can cause the RSVG decoder to free image state twice and then use freed memory, crashing the process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
High
Attack Complexity
PR
None
Privileges Required
UI
None
User Interaction
S
Unchanged
Scope
C
None
Confidentiality
I
None
Integrity
A
High
Availability
References
- advisory[email protected]https://github.com/ImageMagick/ImageMagick/commit/326451aae51ac2dabc99fe66e063de6ec14cf8c8
- advisory[email protected]https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-30
- advisory[email protected]https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-f2r2-qw7g-3c8x
- advisory[email protected]https://github.com/ImageMagick/ImageMagick6/commit/04a4c5b89c034cf2c93bb0a10044332d941b4fa5
- advisory[email protected]https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-55
Related threats
same CWE or vendorCVE-2026-14508 — IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a re…
CVE-2026-14508 · 9h ago
CVE-2026-105824 — ImageMagick before 6.9.13-55 and 7.x before 7.1.2-30 contains a use-after-free vulnerability in the RSVG decoder when built without cairo support, …
CVE-2026-105824 · 9h ago
CVE-2026-107167 — A flaw was found in m17n-lib.
CVE-2026-107167 · 1d ago
CVE-2026-107183 — llama.cpp before b11393 contains a use-after-free and double free vulnerability in common_chat_peg_mapper::map that allows unauthenticated remote a…
CVE-2026-107183 · 1d ago
CVE-2026-55330 — In BluetoothCccHandlerCallbackImpl of bluetooth_ccc.cc, there is a possible use-after-free due to a logic error in the code.
CVE-2026-55330 · 2d ago
CVE-2026-106423 — Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafte…
CVE-2026-106423 · 2d ago