CVE-2026-93589: ImageMagick

Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.

ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for ticks per second in the image being encoded causes a divide-by-zero and crashes the encoder, resulting in a denial of service. The issue is fixed in 7.1.2-31 and 6.9.13-56.

Affected products

  • ImageMagick ImageMagick: before 7.1.2-31 (fixed in 7.1.2-31); before 6.9.13-56 (fixed in 6.9.13-56)

Published 2026-09-18. Last modified 2026-09-22.