CVE-2026-105083

NameCVE-2026-105083
DescriptionImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when policy.xml uses an alternate DOCTYPE. A valid DOCTYPE not ending in ']>' makes the parser consume the rest of the file, so no policy rules are applied and restricted operations become allowed.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
imagemagick (PTS)bookworm8:6.9.11.60+dfsg-1.6+deb12u11vulnerable
bookworm (security)8:6.9.11.60+dfsg-1.6+deb12u13vulnerable
trixie8:7.1.1.43+dfsg1-1+deb13u12vulnerable
trixie (security)8:7.1.1.43+dfsg1-1+deb13u11vulnerable
forky, sid8:7.1.2.31+dfsg1-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
imagemagicksource(unstable)(unfixed)

Notes

https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-jjp4-3fwf-393j
Fixed by: https://github.com/ImageMagick/ImageMagick/commit/1926ccf119141c26274c120d1899dffae19b0c71 (7.1.2-32)
Fixed by: https://github.com/ImageMagick/ImageMagick/commit/399d4bd3b081f44c7fef78153f65e8cdebed9f1a (7.1.2-32)
Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/da6022b2efe6cce8a2fd8f9e51188a45a3b9d558 (6.9.13-57)
Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/402ebc5353e569234908962cbdf451531ff66a57 (6.9.13-57)

Search for package or bug name: Reporting problems