CVE-2026-25794Disclosure(imagemagick / imagemagick)

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch imagemagick imagemagick systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ImageMagick is free and open-source software used for editing and manipulating digital images. `WriteUHDRImage` in `coders/uhdr.c` uses `int` arithmetic to compute the pixel buffer size. Prior to version 7.1.2-15, when image dimensions are large, the multiplication overflows 32-bit `int`, causing an undersized heap allocation followed by an out-of-bounds write. This can crash the process or potentially lead to an out of bounds heap write. Version 7.1.2-15 contains a patch.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-190

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • imagemagick

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 4 mentions (2026-02-24); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Products
imagemagick

Deep dive

Activity timeline7 mentions / 4d
01234Mentions · 2026-02-24: 4Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Mentions · 2026-03-01: 1Patch / Workaround · 2026-02-24: 1Technical Details · 2026-02-24: 4Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-01: 102-2402-2702-2803-01
Signal classification3 categories
Disclosure
457.1%
General
228.6%
Patch
114.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-244
Disclosure3Patch1
2026-02-271
General1
2026-02-281
Disclosure1
2026-03-011
General1
Full discourse7 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25794 Integer Overflow in ImageMagick WriteUHDRImage Leading to Heap Corruption https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25794

    Post summary

    The text announces CVE-2026-25794, an integer overflow in ImageMagick's WriteUHDRImage that can cause heap corruption, with no additional details on PoC, exploitation, or patches.

    0000146
    4.0K followersView on X
  • CVETodo@CveTodo
    Disclosure

    CVE-2026-25794 pertains to a critical flaw in ImageMagick, an open-source image processing software widely used for editing and manipulating digital images. The vulnerability resides in the `WriteUHDRImage` function within the `coders/uhdr.c` source file. Specifically, the function uses 32-bit integer arithmetic to calculate the size of the pixel buffer needed for image processing. When handling images with very large dimensions, this calculation can overflow, resulting in an undersized heap allocation. Subsequently, the program writes beyond the allocated buffer bounds, leading to an out-of-bounds heap write. This flaw can cause application crashes or potentially enable remote code execution. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #DDoS https://cvetodo.com/cve/CVE-2026-25794

    Post summary

    The post discloses a critical integer overflow in ImageMagick’s WriteUHDRImage that can cause out‑of‑bounds heap writes and potentially enable remote code execution, but it does not mention a PoC, exploit, or patch.

    0001051
    20 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-25794 (CVSS:8.2, HIGH) is Analyzed. ImageMagick is free and open-source software used for editing and manipulating digital images. `WriteUHDRImage` in `code..https://nvd.nist.gov/vuln/detail/CVE-2026-25794 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE-2026-25794 with its high severity rating and affected ImageMagick function, but offers no further exploitation or mitigation details.

    0000022
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-25794 (CVSS:8.2, HIGH) is Analyzed. ImageMagick is free and open-source software used for editing and manipulating digital images. `WriteUHDRImage` in `code..https://nvd.nist.gov/vuln/detail/CVE-2026-25794 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces CVE-2026-25794 with a CVSS score of 8.2 and identifies the vulnerable function in ImageMagick, providing only basic technical details and a link to the NVD entry, but no exploit or patch information.

    0000023
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-25794 (CVSS:8.2, HIGH) is Analyzed. ImageMagick is free and open-source software used for editing and manipulating digital images. `WriteUHDRImage` in `code..https://nvd.nist.gov/vuln/detail/CVE-2026-25794 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post notes CVE‑2026‑25794 with a CVSS score of 8.2, indicating the vulnerable function in ImageMagick, but offers no PoC, exploit, or remediation details.

    0000027
    173 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A heap-buffer-overflow (CVE-2026-25794) affects `ImageMagick` via crafted UHDR images. Update to mitigate potential #DoS or #RCE. #infosec https://www.pulsepatch.io/posts/cve-2026-25794-imagemagick-heap-overflow

    Post summary

    ImageMagick suffers a heap‑buffer‑overflow (CVE‑2026‑25794) triggered by crafted UHDR images; an update is recommended to mitigate potential DoS or RCE attacks.

    0000065
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25794 ImageMagick is free and open-source software used for editing and manipulating digital images. `WriteUHDRImage` in `coders/uhdr.c` uses `int` arithmetic to compute th… https://www.cve.org/CVERecord?id=CVE-2026-25794

    Post summary

    The text references CVE-2026-25794, noting that ImageMagick’s WriteUHDRImage function uses int arithmetic, indicating a potential vulnerability.

    00000136
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appimagemagickimagemagick---

Explore more