CVE-2026-23874

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-13 have a stack overflow via infinite recursion in MSL (Magick Scripting Language) `<write>` command when writing to MSL format. Version 7.1.2-13 fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:22

Type Values Removed Values Added
Summary
  • (es) ImageMagick es un software libre y de código abierto utilizado para editar y manipular imágenes digitales. Las versiones anteriores a la 7.1.2-13 tienen un desbordamiento de pila mediante recursión infinita en el comando `` de MSL (Magick Scripting Language) al escribir en formato MSL. La versión 7.1.2-13 corrige el problema.

29 Jan 2026, 13:57

Type Values Removed Values Added
CPE cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
References () https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9vj4-wc7r-p844 - () https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9vj4-wc7r-p844 - Exploit, Vendor Advisory
First Time Imagemagick
Imagemagick imagemagick

20 Jan 2026, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-20 01:15

Updated : 2026-06-17 10:22


NVD link : CVE-2026-23874

Mitre link : CVE-2026-23874

CVE.ORG link : CVE-2026-23874


JSON object : View

Products Affected

imagemagick

  • imagemagick
CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')