ImageMagick Denial-of-Service Vulnerability Due to Infinite Loop in IPTCTEXT Processing

Vulnerability

A denial-of-service vulnerability has been identified in ImageMagick versions prior to 7.1.2-15 and 6.9.13-40. The issue arises when a crafted profile containing invalid IPTC data is processed with 'IPTCTEXT', leading to an infinite loop. This vulnerability requires no privileges or user interaction to exploit.

Impact

Exploitation of this vulnerability causes an infinite loop, which can lead to a denial-of-service condition by consuming system resources and potentially causing the application to become unresponsive.

Remediation

Users can upgrade to ImageMagick versions 7.1.2-15 or 6.9.13-40 to address this vulnerability.

Added: Feb 24, 2026, 3:29 AM
Updated: Feb 24, 2026, 3:29 AM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
2.5
exploitability
3.3
remediation
7.7
relevance
3.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.