CVE-2026-25985 is a high-severity vulnerability affecting ImageMagick versions prior to 7.1.2-15 and 6.9.13-40. A specially crafted SVG file can trigger an out-of-memory condition, causing the application to crash by attempting to allocate approximately 674 GB of memory. This vulnerability has a CVSS score of 7.5 (HIGH) due to its network-based attack vector, low attack complexity, and high availability impact, requiring no user interaction or privileges. While there is no known active exploitation, public exploit code, or KEV entry, the vulnerability has garnered significant community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.9.13-40CPE matchmatch criteria | cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:* | ||
>= 7.0.0-0, < 7.1.2-15CPE matchmatch criteria | cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.