CVE-2026-102635

Published: Set 29, 2026 Last Modified: Set 29, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 6,3
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
LOW 3,7
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: none
Availability: none

Description

AI Translation Available

ImageMagick versions before 7.1.2-32 and 6.9.13-57 contain uninitialized heap memory disclosure in the GIF decoder's application extension handler in coders/gif.c. Attackers can craft malicious GIF files that cause the number parser to read uninitialized heap memory and store contents as image metadata, disclosing sensitive heap information.

908

Use of Uninitialized Resource

Incomplete
Common Consequences
Security Scopes Affected:
Confidentiality Availability
Potential Impacts:
Read Memory Read Application Data Dos: Crash, Exit, Or Restart
Applicable Platforms
All platforms may be affected
View CWE Details
https://github.com/ImageMagick/ImageMagick
https://github.com/ImageMagick/ImageMagick6/commit/95dc0fd21a684bfac2bdb6fb6638…
https://github.com/ImageMagick/ImageMagick/blob/7.1.2-31/coders/gif.c#L1168-L11…
https://github.com/ImageMagick/ImageMagick/commit/a0ca2c739c0216ff4efbd631d1ba7…
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-rvv7-5mh8-v…
https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-32-and-6.9.13-57-…