CVE-2026-26283Disclosure(imagemagick / imagemagick)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a `continue` statement in the JPEG extent binary search loop in the jpeg encoder causes an infinite loop when writing persistently fails. An attacker can trigger a 100% CPU consumption and process hang (Denial of Service) with a crafted image. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-835

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • imagemagick

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Products
imagemagick

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-24: 3Technical Details · 2026-02-24: 202-24
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26283 ImageMagick Denial of Service via Infinite Loop in JPEG Encoder Before 7.1.2-15 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26283

    Post summary

    The text announces a denial‑of‑service vulnerability (CVE‑2026‑26283) in ImageMagick’s JPEG encoder affecting versions prior to 7.1.2‑15, with no mention of PoC, exploit, or patch.

    0000150
    4.0K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-26283: The Eternal JPEG: Infinite Loops in ImageMagick's Optimization Logic A critical Denial of Service (DoS) vulnerability in ImageMagick's JPEG encoder allows attackers to trigger an infinite loop by abusing the `jpeg:extent` feature. By f... https://cvereports.com/reports/CVE-2026-26283

    Post summary

    A new DoS vulnerability (CVE-2026-26283) in ImageMagick’s JPEG encoder is disclosed, allowing attackers to trigger infinite loops via the jpeg:extent feature, but no PoC, exploit, or patch details are provided.

    0000051
    31 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-26283 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a `continue` statement in the… https://www.cve.org/CVERecord?id=CVE-2026-26283

    Post summary

    The text references CVE-2026-26283 affecting ImageMagick before certain versions, but provides no details on exploitation, patches, or PoC.

    0000091
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appimagemagickimagemagick---

Explore more