CVE Explorer
CVE-2026-24485
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, when a PCD file does not contain a valid Sync marker, the DecodeImage() function becomes trapped in an infinite loop while searching for the Sync marker, causing the program to become unresponsive and continuously consume CPU resources, ultimately leading to system resource exhaustion and denial of service. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"ImageMagick","vendor":"ImageMagick","versions":[{"status":"affected","version":">= 7.0.0, < 7.1.2-15"},{"status":"affected","version":"< 6.9.13-40"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:e408db998baac20e23c858b4377a495ca490ee9ef7a7e77ece0ae594da17fa1f · sha256:e2ecb726a69717ba… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:e408db998baac20e23c858b4377a495ca490ee9ef7a7e77ece0ae594da17fa1f · sha256:e2ecb726a69717ba… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-400","description":"CWE-400: Uncontrolled Resource Consumption","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:e408db998baac20e23c858b4377a495ca490ee9ef7a7e77ece0ae594da17fa1f · sha256:e2ecb726a69717ba… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/ImageMagick/ImageMagick/commit/332c1566acc2de77857032d3c2504ead6210ff50","tags":["x_refsource_MISC"],"url":"https://github.com/ImageMagick/ImageMagick/commit/332c1566acc2de77857032d3c2504ead6210ff50"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e408db998baac20e23c858b4377a495ca490ee9ef7a7e77ece0ae594da17fa1f · sha256:e2ecb726a69717ba… · /containers/cna/references/1
{"name":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-pqgj-2p96-rx85","tags":["x_refsource_CONFIRM"],"url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-pqgj-2p96-rx85"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e408db998baac20e23c858b4377a495ca490ee9ef7a7e77ece0ae594da17fa1f · sha256:e2ecb726a69717ba… · /containers/cna/references/0
{"name":"https://github.com/dlemstra/Magick.NET/releases/tag/14.10.3","tags":["x_refsource_MISC"],"url":"https://github.com/dlemstra/Magick.NET/releases/tag/14.10.3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e408db998baac20e23c858b4377a495ca490ee9ef7a7e77ece0ae594da17fa1f · sha256:e2ecb726a69717ba… · /containers/cna/references/2
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.