CVE-2026-23874: ImageMagick

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-13 have a stack overflow via infinite recursion in MSL (Magick Scripting Language) `<write>` command when writing to MSL format. Version 7.1.2-13 fixes the issue.

Affected products

  • ImageMagick ImageMagick: before 7.1.2-13 (fixed in 7.1.2-13)

Published 2026-01-20. Last modified 2026-06-17.