CVE-2026-105827
MEDIUM
NVD
CVSS Score
5.3
Severity
MEDIUM
Published
Oct 08, 2026
Vendor
unknown
Description
ImageMagick before 7.1.2-30 and 6.9.13-55 contains an uncontrolled recursion vulnerability in the CALS decoder due to a missing depth check. Attackers can supply a crafted CALS image that triggers unbounded recursion, exhausting the stack and crashing the process, resulting in a denial of service.