OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-105405 (CVSS 8.2)

NVD · officialPublished Oct 8, 2026Risk 37/100

ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 contains an invalid memory free vulnerability in the MVG decoder. Attackers can supply a crafted MVG image for processing to trigger the invalid free and crash the application, causing a denial of service.

CVSS
8.2
AV:NetworkAC:HighPR:NoneUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source