CVE-2026-23952NULL Pointer Dereference in Imagemagick

Severity
7.5HIGHNVD
EPSS
0.0%
top 94.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 22
Latest updateMar 30

Description

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL (Magick Scripting Language) parser when processing tags before images are loaded. This can lead to DoS attack due to assertion failure (debug builds) or NULL pointer dereference (release builds). This issue is fixed in version 14.10.2.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages6 packages

debiandebian/imagemagick< imagemagick 8:6.9.11.60+dfsg-1.6+deb12u6 (bookworm)
CVEListV5imagemagick/imagemagick< 14.10.2
NVDimagemagick/imagemagick7.0.0-07.1.2-13+1
Debianimagemagick/imagemagick< 8:6.9.11.60+dfsg-1.3+deb11u9+3
Ubuntuimagemagick/imagemagick< 8:6.7.7.10-6ubuntu3.13+esm20+5

🔴Vulnerability Details

4
OSV
imagemagick vulnerabilities2026-03-30
OSV
CVE-2026-23952: ImageMagick is free and open-source software used for editing and manipulating digital images2026-01-22
OSV
ImageMagick has a NULL pointer dereference in MSL parser via <comment> tag before image load2026-01-21
GHSA
ImageMagick has a NULL pointer dereference in MSL parser via <comment> tag before image load2026-01-21

📋Vendor Advisories

3
Ubuntu
ImageMagick vulnerabilities2026-03-30
Red Hat
ImageMagick: ImageMagick: Denial of Service via processing of MSL comment tags2026-01-22
Debian
CVE-2026-23952: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-23952 Impact, Exploitability, and Mitigation Steps | Wiz