CVE-2026-23952
published 2026-01-22CVE-2026-23952: ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and below have a NULL pointer dereference…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.43%
35.2th percentile
ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL (Magick Scripting Language) parser when processing tags before images are loaded. This can lead to DoS attack due to assertion failure (debug builds) or NULL pointer dereference (release builds). This issue is fixed in version 14.10.2.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imagemagick | < imagemagick 8:6.9.11.60+dfsg-1.6+deb12u6 (bookworm) | imagemagick 8:6.9.11.60+dfsg-1.6+deb12u6 (bookworm) |
| dlemstra | magick.net | < 14.10.2 | 14.10.2 |
| imagemagick | imagemagick | < 14.10.2 | 14.10.2 |
| imagemagick | imagemagick | < 6.9.13-38 | 6.9.13-38 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.3+deb11u9 | 8:6.9.11.60+dfsg-1.3+deb11u9 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.6+deb12u6 | 8:6.9.11.60+dfsg-1.6+deb12u6 |
| imagemagick | imagemagick | >= 0 < 8:7.1.1.43+dfsg1-1+deb13u5 | 8:7.1.1.43+dfsg1-1+deb13u5 |
| imagemagick | imagemagick | >= 0 < 8:7.1.2.13+dfsg1-1 | 8:7.1.2.13+dfsg1-1 |
| imagemagick | imagemagick | >= 0 < 8:6.7.7.10-6ubuntu3.13+esm20 | 8:6.7.7.10-6ubuntu3.13+esm20 |
| imagemagick | imagemagick | >= 0 < 8:6.8.9.9-7ubuntu5.16+esm19 | 8:6.8.9.9-7ubuntu5.16+esm19 |
| imagemagick | imagemagick | >= 0 < 8:6.9.7.4+dfsg-16ubuntu6.15+esm11 | 8:6.9.7.4+dfsg-16ubuntu6.15+esm11 |
| imagemagick | imagemagick | >= 0 < 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm9 | 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm9 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm9 | 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm9 |
| imagemagick | imagemagick | >= 0 < 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm8 | 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm8 |
| imagemagick | imagemagick | >= 7.0.0-0 < 7.1.2-13 | 7.1.2-13 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2026-03-30·CVSS 6.5
CVE-2026-25799 [MEDIUM] ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: Several security issues were fixed in ImageMagick.
It was discovered that ImageMagick did not properly process certain tags
prior to an image being loaded. An attacker could possibly use this issue
to cause ImageMagick to crash, resulting in a denial of service.
(CVE-2026-23952)
It was discovered that ImageMagick did not properly handle temporary file
creation failures. An attacker could possibly use this issue to cause
ImageMagick to crash, resulting in a denial of service. (CVE-2026-25795)
It was discovered that ImageMagick did not properly manage memory under
certain conditions. An attacker could possibly use this issue to cause
ImageMagick to consume resources, resulting in a denial of service.
(CVE-2026-25796)
It was discovered that Ima
Red Hat
ImageMagick: ImageMagick: Denial of Service via processing of MSL comment tags
vendor_redhat·2026-01-22·CVSS 6.5
CVE-2026-23952 [MEDIUM] CWE-476 ImageMagick: ImageMagick: Denial of Service via processing of MSL comment tags
ImageMagick: ImageMagick: Denial of Service via processing of MSL comment tags
ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL (Magick Scripting Language) parser when processing tags before images are loaded. This can lead to DoS attack due to assertion failure (debug builds) or NULL pointer dereference (release builds). This issue is fixed in version 14.10.2.
A flaw was found in ImageMagick. A remote attacker could exploit a NULL pointer dereference vulnerability in the Magick Scripting Language (MSL) parser. This occurs when processing tags before images are loaded. Successful exploitation can lead to a Denial of Service (DoS) attack, making the software un
Debian
CVE-2026-23952: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
vendor_debian·2026·CVSS 6.5
CVE-2026-23952 [MEDIUM] CVE-2026-23952: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL (Magick Scripting Language) parser when processing tags before images are loaded. This can lead to DoS attack due to assertion failure (debug builds) or NULL pointer dereference (release builds). This issue is fixed in version 14.10.2.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.60+dfsg-1.6+deb12u6)
bullseye: resolved (fixed in 8:6.9.11.60+dfsg-1.3+deb11u9)
forky: resolved (fixed in 8:7.1.2.13+dfsg1-1)
sid: resolved (fixed in 8:7.1.2.13+dfsg1-1)
trixie: resolved (fixed in 8:7.1.1.43+dfsg1-1+deb13u5)
OSV
imagemagick vulnerabilities
osv·2026-03-30·CVSS 7.5
CVE-2026-23952 [HIGH] imagemagick vulnerabilities
imagemagick vulnerabilities
It was discovered that ImageMagick did not properly process certain tags
prior to an image being loaded. An attacker could possibly use this issue
to cause ImageMagick to crash, resulting in a denial of service.
(CVE-2026-23952)
It was discovered that ImageMagick did not properly handle temporary file
creation failures. An attacker could possibly use this issue to cause
ImageMagick to crash, resulting in a denial of service. (CVE-2026-25795)
It was discovered that ImageMagick did not properly manage memory under
certain conditions. An attacker could possibly use this issue to cause
ImageMagick to consume resources, resulting in a denial of service.
(CVE-2026-25796)
It was discovered that ImageMagick incorrectly handled certain specially
crafted image files.
OSV
CVE-2026-23952: ImageMagick is free and open-source software used for editing and manipulating digital images
osv·2026-01-22·CVSS 7.5
CVE-2026-23952 [HIGH] CVE-2026-23952: ImageMagick is free and open-source software used for editing and manipulating digital images
ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL (Magick Scripting Language) parser when processing tags before images are loaded. This can lead to DoS attack due to assertion failure (debug builds) or NULL pointer dereference (release builds). This issue is fixed in version 14.10.2.
OSV
ImageMagick has a NULL pointer dereference in MSL parser via <comment> tag before image load
osv·2026-01-21
CVE-2026-23952 [MEDIUM] ImageMagick has a NULL pointer dereference in MSL parser via <comment> tag before image load
ImageMagick has a NULL pointer dereference in MSL parser via tag before image load
## Summary
NULL pointer dereference in MSL (Magick Scripting Language) parser when processing `` tag before any image is loaded.
## Version
- ImageMagick 7.x (tested on current main branch)
- Commit: HEAD
## Steps to Reproduce
### Method 1: Using ImageMagick directly
```bash
magick MSL:poc.msl out.png
```
### Method 2: Using OSS-Fuzz reproduce
```bash
python3 infra/helper.py build_fuzzers imagemagick
python3 infra/helper.py reproduce imagemagick msl_fuzzer poc.msl
```
Or run the fuzzer directly:
```bash
./msl_fuzzer poc.msl
```
## Expected Behavior
ImageMagick should handle the malformed MSL gracefully and return an error message.
## Actual Behavior
```
convert: MagickCore/property.c:297: Magic
GHSA
ImageMagick has a NULL pointer dereference in MSL parser via <comment> tag before image load
ghsa·2026-01-21
CVE-2026-23952 [MEDIUM] CWE-476 ImageMagick has a NULL pointer dereference in MSL parser via <comment> tag before image load
ImageMagick has a NULL pointer dereference in MSL parser via tag before image load
## Summary
NULL pointer dereference in MSL (Magick Scripting Language) parser when processing `` tag before any image is loaded.
## Version
- ImageMagick 7.x (tested on current main branch)
- Commit: HEAD
## Steps to Reproduce
### Method 1: Using ImageMagick directly
```bash
magick MSL:poc.msl out.png
```
### Method 2: Using OSS-Fuzz reproduce
```bash
python3 infra/helper.py build_fuzzers imagemagick
python3 infra/helper.py reproduce imagemagick msl_fuzzer poc.msl
```
Or run the fuzzer directly:
```bash
./msl_fuzzer poc.msl
```
## Expected Behavior
ImageMagick should handle the malformed MSL gracefully and return an error message.
## Actual Behavior
```
convert: MagickCore/property.c:297: Magic
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-23952 ImageMagick: ImageMagick: Denial of Service via processing of MSL comment tags [fedora-42]
bugzilla·2026-01-22·CVSS 7.5
CVE-2026-23952 [HIGH] CVE-2026-23952 ImageMagick: ImageMagick: Denial of Service via processing of MSL comment tags [fedora-42]
CVE-2026-23952 ImageMagick: ImageMagick: Denial of Service via processing of MSL comment tags [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained
Wiz
CVE-2026-23952 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-23952 [MEDIUM] CVE-2026-23952 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23952 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL (Magick Scripting Language) parser when processing tags before images are loaded. This can lead to DoS attack due to assertion failure (debug builds) or NULL pointer dereference (release builds). This issue is fixed in version 14.10.2.
Source : NVD
## 7.5
Score
Published January 22, 2026
Severity HIGH
CNA Score 6.5
Affected Technologies
C#
ImageMagick
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.6
Exploitation Probability (EPSS) N/A
Affected
2026-01-22
Published