FAIL › dossier
imagemagick
VENDOR· dossier confidence 20%
ImageMagick is a widely used open-source image manipulation tool with a documented history of severe security vulnerabilities, including remote code execution and server-side request forgery. Its security posture remains a concern due to active exploitation of known flaws like CVE-2016-3715, requiring strict patching and configuration controls in defense-industrial environments.
ImageMagick has a historically poor security posture, with multiple high-severity vulnerabilities including remote code execution (RCE), server-side request forgery (SSRF), and heap buffer overflows. The software remains actively exploited in the wild, particularly CVE-2016-3715, which allows arbitrary file deletion via an ephemeral pseudo protocol.
- CVE-2016-3714 RCE via shell metacharacters
- CVE-2016-3715 ephemeral pseudo protocol file deletion
- CVE-2016-3718 SSRF via crafted images
- CVE-2026-56372 heap buffer overflow in magnify operation
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2024-09-09 | CVE-2016-3714 | high | ImageMagick's CVE-2016-3714 allows remote attackers to execute arbitrary code via shell metacharacters in crafted images. |
| 2024-09-09 | CVE-2016-3714 | high | ImageMagick's CVE-2016-3714 allows remote attackers to execute arbitrary code via shell metacharacters in crafted images. |
| 2021-11-03 | CVE-2016-3715 | high | ImageMagick's ephemeral pseudo protocol allowed arbitrary file deletion, a known vulnerability (CVE-2016-3715) that remains actively exploited in the wild. |
| 2021-11-03 | CVE-2016-3715 | high | ImageMagick's ephemeral pseudo protocol allowed arbitrary file deletion, a known vulnerability (CVE-2016-3715) that remains actively exploited in the wild. |
| 2021-11-03 | CVE-2016-3718 | high | An SSRF vulnerability in ImageMagick allowed attackers to forge server requests via crafted images, leading to potential data exfiltration or internal network access. |
| 2021-11-03 | CVE-2016-3718 | high | An SSRF vulnerability in ImageMagick allowed attackers to forge server requests via crafted images, leading to potential data exfiltration or internal network access. |
| 2026-07-11 | CVE-2026-56372 | low | ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. An unrecognized magnify:method value triggers an out of bounds read, potentially exposing sensitive information or causing denial |
| 2026-07-11 | CVE-2026-56372 | low | ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. An unrecognized magnify:method value triggers an out of bounds read, potentially exposing sensitive information or causing denial |
| 2026-01-20 | CVE-2026-23876 | high | CVE-2026-23876: ImageMagick is free and open-source software used for editing and manipulating d |
| 2026-01-20 | CVE-2026-23876 | high | CVE-2026-23876: ImageMagick is free and open-source software used for editing and manipulating d |
"ImageMagick contains an unspecified vulnerability that allows attackers to perform server-side request forgery (SSRF) via a crafted image."
"ImageMagick contains an unspecified vulnerability that could allow users to delete files by using ImageMagick's 'ephemeral' pseudo protocol, which deletes files after reading."
- Package: mingw-w64-x86_64-imagemagick - MSYS2 Packages · packages.msys2.org
- The vulnerability of the console-based graphic editor ImageMagick ... · vulners.com
- Download ImageMagick 7.1.2-30 - MajorGeeks · www.majorgeeks.com