cbcvebase.
CVE-2025-55004
published 2025-08-13

CVE-2025-55004: ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, ImageMagick is vulnerable to…

PriorityP421medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
EPSS
0.52%
40.8th percentile
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, ImageMagick is vulnerable to heap-buffer overflow read around the handling of images with separate alpha channels when performing image magnification in ReadOneMNGIMage. This can likely be used to leak subsequent memory contents into the output image. This issue has been patched in version 7.1.2-1.

Affected

4 ranges
VendorProductVersion rangeFixed in
debianimagemagick< imagemagick 8:7.1.2.1+dfsg1-1 (forky)imagemagick 8:7.1.2.1+dfsg1-1 (forky)
imagemagickimagemagick< 7.1.2-17.1.2-1
imagemagickimagemagick>= 0 < 8:7.1.1.43+dfsg1-1+deb13u28:7.1.1.43+dfsg1-1+deb13u2
imagemagickimagemagick>= 0 < 8:7.1.2.1+dfsg1-18:7.1.2.1+dfsg1-1

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
osv4.3MEDIUM
vendor_debian7.6LOW
vendor_redhat7.6HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.