{"id":"CVE-2026-86420","aliases":["GHSA-4mwf-mggw-29vp"],"url":"https://o3.security/vulnerability/CVE-2026-86420","summary":"ImageMagick before 7.1.2-30 Denial of Service Memory Budget","details":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service.","published":"2026-09-07T12:53:43.875Z","modified":"2026-09-10T03:31:00.703723584Z","cvss":null,"epss":{"score":0.00273,"percentile":0.19555,"asOf":"2026-09-09"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86420.json"},{"type":"ADVISORY","url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4mwf-mggw-29vp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86420"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-denial-of-service-memory-budget"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:31:00.703723584Z"}}