CVE-2026-45664 PUBLISHED

ImageMagick: Policy Bypass in MNG coder could

Assigner: GitHub_M
Reserved: 12.05.2026 Published: 10.06.2026 Updated: 11.06.2026

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, because of a missing check in the MNG coder it would be possible to read more images than the list limit policy would allow resulting in excessive resource use. This issue has been patched in versions 6.9.13-47 and 7.1.2-22.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS Score: 5.3

Product Status

Vendor ImageMagick
Product ImageMagick
Versions
  • Version < 6.9.13-47 is affected
  • Version < 7.1.2-22 is affected

References

Problem Types

  • CWE-400: Uncontrolled Resource Consumption CWE
  • CWE-407: Inefficient Algorithmic Complexity CWE
  • CWE-674: Uncontrolled Recursion CWE