CVE-2026-105402
MEDIUM
NVD
CVSS Score
5.3
Severity
MEDIUM
Published
Oct 08, 2026
Vendor
unknown
Description
ImageMagick before 7.1.2-31 contains a denial of service vulnerability that allows attackers to disrupt processing by supplying a crafted XMP profile. Attackers can embed a malicious XMP profile that triggers a failure when determining the numerator and denominator, crashing or hanging image processing.