CVE-2026-55577
Public on 2026-07-01
Modified on 2026-09-10
Description
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | ImageMagick | 2026-09-28 | ALAS2-2026-3939 | Fixed |
| Amazon Linux 2023 | ImageMagick | 2026-09-29 | ALAS2023-2026-3115 | Fixed |
| Amazon Linux 2027 Preview | ImageMagick | Not Affected |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 5.9 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |