ImageMagick Out-of-Memory Denial-of-Service Vulnerability in SVG Processing

Vulnerability

A denial-of-service vulnerability has been identified in ImageMagick versions prior to 7.1.2-15 and 6.9.13-40. The issue arises in the internal SVG decoder, where a crafted SVG file containing a malicious element can cause ImageMagick to attempt to allocate approximately 674 GB of memory. This excessive memory allocation leads to an out-of-memory error, causing the application to abort. The vulnerability was discovered through fuzz testing with AFL++.

Impact

Exploitation of this vulnerability causes the application to run out of memory and abort, disrupting any ongoing processes that involve image processing or manipulation.

Remediation

Users can upgrade to ImageMagick versions 7.1.2-15 or 6.9.13-40 to address this vulnerability.

Added: Feb 24, 2026, 2:19 AM
Updated: Feb 24, 2026, 2:19 AM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
2.5
exploitability
4.3
remediation
7.7
relevance
3.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.