PT-2026-3527 · Unknown · Imagemagick

Owensanzas

·

Published

2026-01-16

·

Updated

2026-03-09

·

CVE-2026-23874

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ImageMagick versions prior to 7.1.2-13
Description ImageMagick is software used for editing and manipulating digital images. Versions before 7.1.2-13 are susceptible to a stack overflow due to infinite recursion within the MSL (Magick Scripting Language) <write> command when writing to MSL format. The issue is addressed in version 7.1.2-13.
Recommendations Update to version 7.1.2-13 or later.

Exploit

Fix

Infinite Loop

Weakness Enumeration

Related Identifiers

BDU:2026-00643
CVE-2026-23874
ECHO-B019-22D4-4AE0
GHSA-9VJ4-WC7R-P844
OESA-2026-1241
OESA-2026-1242
OESA-2026-1243
OESA-2026-1244
OESA-2026-1245
OESA-2026-1246
OPENSUSE-SU-2026:10119-1
OPENSUSE-SU-2026:20337-1
SUSE-SU-2026:0384-1
SUSE-SU-2026:0437-1
SUSE-SU-2026:0438-1
SUSE-SU-2026:0503-1

Affected Products

Imagemagick