๐Ÿ” CVE Alert

CVE-2026-102635

LOW 3.7

ImageMagick before 7.1.2-32 and 6.9.13-57 Uninitialized Heap Memory Disclosure in GIF Decoder

CVSS Score
3.7
EPSS Score
0.0%
EPSS Percentile
0th

ImageMagick versions before 7.1.2-32 and 6.9.13-57 contain uninitialized heap memory disclosure in the GIF decoder's application extension handler in coders/gif.c. Attackers can craft malicious GIF files that cause the number parser to read uninitialized heap memory and store contents as image metadata, disclosing sensitive heap information.

CWE CWE-908
Vendor imagemagick
Product imagemagick
Published Sep 29, 2026
Stay Ahead of the Next One

Get instant alerts for imagemagick imagemagick

Be the first to know when new low vulnerabilities affecting imagemagick imagemagick are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

ImageMagick / ImageMagick
7.0.0-0 < 7.1.2-32 0 < 6.9.13-57

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-rvv7-5mh8-vcfc github.com: https://github.com/ImageMagick/ImageMagick/commit/a0ca2c739c0216ff4efbd631d1ba7fd54dba1ff4 github.com: https://github.com/ImageMagick/ImageMagick6/commit/95dc0fd21a684bfac2bdb6fb6638c0ab271adbe5 github.com: https://github.com/ImageMagick/ImageMagick/blob/7.1.2-31/coders/gif.c#L1168-L1196 github.com: https://github.com/ImageMagick/ImageMagick vulncheck.com: https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-32-and-6.9.13-57-uninitialized-heap-memory-disclosure-in-gif-decoder

Credits

idoprog