CVE-2026-45664

MEDIUM

ImageMagick: Policy Bypass in MNG coder could

Title source: cna
STIX 2.1

Description

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, because of a missing check in the MNG coder it would be possible to read more images than the list limit policy would allow resulting in excessive resource use. This issue has been patched in versions 6.9.13-47 and 7.1.2-22.

References (1)

Core 1
Core References

Scores

CVSS v3 5.3
EPSS 0.0040
EPSS Percentile 31.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-400 CWE-407 CWE-674
Status published
Products (21)
imagemagick/imagemagick < 6.9.13-47
ImageMagick/ImageMagick < 6.9.13-47
ImageMagick/ImageMagick < 7.1.2-22
nuget/Magick.NET-Q16-AnyCPU 0 - 14.13.1NuGet
nuget/Magick.NET-Q16-arm64 0 - 14.13.1NuGet
nuget/Magick.NET-Q16-HDRI-AnyCPU 0 - 14.13.1NuGet
nuget/Magick.NET-Q16-HDRI-arm64 0 - 14.13.1NuGet
nuget/Magick.NET-Q16-HDRI-OpenMP-arm64 0 - 14.13.1NuGet
nuget/Magick.NET-Q16-HDRI-OpenMP-x64 0 - 14.13.1NuGet
nuget/Magick.NET-Q16-HDRI-x64 0 - 14.13.1NuGet
... and 11 more
Published Jun 10, 2026
Tracked Since Jun 11, 2026