Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-105083

LOW NVD
CVSS Score 3.9
Severity LOW
Published Oct 03, 2026
Vendor unknown

Description

ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when policy.xml uses an alternate DOCTYPE. A valid DOCTYPE not ending in ']>' makes the parser consume the rest of the file, so no policy rules are applied and restricted operations become allowed.

References