low · CVSS v3 2.9 · CVSS v4 2.1
CVE-2026-93586
ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, cau…
Description
ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, caused by a pointer that is not updated correctly. Exploitation may result in a limited availability impact (e.g., a crash of the affected process). The issue is fixed in versions 7.1.2-31 and 6.9.13-56.
Scores
- Severity
- low
- CVSS v2
- 1.2
- CVSS v3
- 2.9
- CVSS v4
- 2.1
- EPSS
- —