CVE-2026-106565

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-835

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-09: 110-09
Full discourse1 post
  • Rıdvan Yağlı@ridvanyagli

    🔴 ImageMagick'te hizmet engellemeye (DoS) yol açabilen 18 orta seviye güvenlik açığı tespit edildi. 🔎 Öne çıkan CVE'ler: • CVE-2026-106565 — Bzip2 verisinin işlenmesinde sonsuz döngü ve kaynak tüketimi • CVE-2026-106567 — PSD dosyalarının işlenmesinde sonsuz döngü (32-bit sistemler) • CVE-2026-106568 — Görsellere gömülü XMP profilinin işlenmesinde sonsuz döngü ✅ Düzeltildiği belirtilen sürümler: 7.1.2-32 ve 6.9.13-57. ImageMagick kullanan sunucuların sürümlerini kontrol etmeleri ve güncellemeleri uygulamaları önerilir.

    00010233
    2.4K followersView on X

Explore more