Vulnerability Description
ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer allocation for image pixels. Attackers can bypass resource policies by processing specially crafted UHDR images, potentially causing denial of service through excessive memory allocation.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7hjx-392p-f8
- https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-31-policy-bypass-i
FAQ
What is CVE-2026-93590?
CVE-2026-93590 is a vulnerability with a CVSS score of 3.7 (LOW). ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer allocation for image pixels. Attackers can bypass resource poli...
How severe is CVE-2026-93590?
CVE-2026-93590 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-93590?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.