CVE-2026-93590: ImageMagick

Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.

ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer allocation for image pixels. Attackers can bypass resource policies by processing specially crafted UHDR images, potentially causing denial of service through excessive memory allocation.

Affected products

  • ImageMagick ImageMagick: before 7.1.2-31 (fixed in 7.1.2-31)

Published 2026-09-18. Last modified 2026-09-22.