ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, when a PCD file does not contain a valid Sync marker, the DecodeImage() function becomes trapped in an infinite loop while searching for the Sync marker, causing the program to become unresponsive and continuously consume CPU resources, ultimately leading to system resource exhaustion and denial of service. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
References
| Link | Resource |
|---|---|
| https://github.com/ImageMagick/ImageMagick/commit/332c1566acc2de77857032d3c2504ead6210ff50 | Patch |
| https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-pqgj-2p96-rx85 | Vendor Advisory |
| https://github.com/dlemstra/Magick.NET/releases/tag/14.10.3 | Product Release Notes |
Configurations
History
27 Feb 2026, 14:34
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Dlemstra
Imagemagick imagemagick Dlemstra magick.net Imagemagick |
|
| CPE | cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:* cpe:2.3:a:dlemstra:magick.net:*:*:*:*:*:*:*:* |
|
| Summary |
|
|
| References | () https://github.com/ImageMagick/ImageMagick/commit/332c1566acc2de77857032d3c2504ead6210ff50 - Patch | |
| References | () https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-pqgj-2p96-rx85 - Vendor Advisory | |
| References | () https://github.com/dlemstra/Magick.NET/releases/tag/14.10.3 - Product, Release Notes |
24 Feb 2026, 01:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-24 01:16
Updated : 2026-02-27 14:34
NVD link : CVE-2026-24485
Mitre link : CVE-2026-24485
CVE.ORG link : CVE-2026-24485
JSON object : View
Products Affected
imagemagick
- imagemagick
dlemstra
- magick.net
CWE
CWE-400
Uncontrolled Resource Consumption
