CVE-2026-23874

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-13 have a stack overflow via infinite recursion in MSL (Magick Scripting Language) `<write>` command when writing to MSL format. Version 7.1.2-13 fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*

History

29 Jan 2026, 13:57

Type Values Removed Values Added
CPE cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
References () https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9vj4-wc7r-p844 - () https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9vj4-wc7r-p844 - Exploit, Vendor Advisory
First Time Imagemagick
Imagemagick imagemagick

20 Jan 2026, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-20 01:15

Updated : 2026-01-29 13:57


NVD link : CVE-2026-23874

Mitre link : CVE-2026-23874

CVE.ORG link : CVE-2026-23874


JSON object : View

Products Affected

imagemagick

  • imagemagick
CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')