Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4539-1 | imagemagick security update |
Debian DSA |
DSA-6158-1 | imagemagick security update |
Debian DSA |
DSA-6210-1 | imagemagick security update |
Github GHSA |
GHSA-v7g2-m8c5-mf84 | ImageMagick: Memory allocation with excessive without limits in the internal SVG decoder |
Sat, 28 Feb 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 25 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:* |
Tue, 24 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 24 Feb 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Imagemagick
Imagemagick imagemagick |
|
| Vendors & Products |
Imagemagick
Imagemagick imagemagick |
Tue, 24 Feb 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted SVG file containing an malicious element causes ImageMagick to attempt to allocate ~674 GB of memory, leading to an out-of-memory abort. Versions 7.1.2-15 and 6.9.13-40 contain a patch. | |
| Title | Memory allocation with excessive without limits in the internal SVG decoder | |
| Weaknesses | CWE-770 CWE-789 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-28T02:05:55.678Z
Reserved: 2026-02-09T17:41:55.857Z
Link: CVE-2026-25985
Updated: 2026-02-28T02:05:49.993Z
Status : Analyzed
Published: 2026-02-24T02:16:02.620
Modified: 2026-02-25T12:10:42.060
Link: CVE-2026-25985
OpenCVE Enrichment
Updated: 2026-04-16T16:45:25Z
Debian DLA
Debian DSA
Github GHSA