ImageMagick versions before 7.1.2-32 and 6.9.13-57 contain uninitialized heap memory disclosure in the GIF decoder's application extension handler in coders/gif.c. Attackers can craft malicious GIF files that cause the number parser to read uninitialized heap memory and store contents as image metadata, disclosing sensitive heap information.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 29 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description ImageMagick versions before 7.1.2-32 and 6.9.13-57 contain uninitialized heap memory disclosure in the GIF decoder's application extension handler in coders/gif.c. Attackers can craft malicious GIF files that cause the number parser to read uninitialized heap memory and store contents as image metadata, disclosing sensitive heap information.
Title ImageMagick before 7.1.2-32 and 6.9.13-57 Uninitialized Heap Memory Disclosure in GIF Decoder
First Time appeared Imagemagick
Imagemagick imagemagick
Weaknesses CWE-908
CPEs cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
Vendors & Products Imagemagick
Imagemagick imagemagick
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-29T16:04:18.036Z

Reserved: 2026-09-29T15:50:38.575Z

Link: CVE-2026-102635

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T17:17:07.323

Modified: 2026-09-29T17:17:07.323

Link: CVE-2026-102635

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses