CVE-2026-46693
4.1 MEDIUMImageMagick is free and open-source software used for editing and manipulating digital images
Published: 2026-06-10 · Last updated: 2026-06-10
Severity and scoring
- CVSS
- 4.1 MEDIUM
- Vector
- CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
- CWE
- CWE-362, CWE-567
Description
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker who can connect to a magick -distribute-cache service can hijack a file descriptor in the server process when a race condition is met. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.
Source: NVD
References
Related CVEs
Same CWE
- CVE-2026-44693 — Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker (8.8 HIGH)
- CVE-2022-26758 — A malicious application may cause unexpected changes in memory shared between processes (7.1 HIGH)
- CVE-2026-1220 — Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a crafted HTML page (7.5 HIGH)
- CVE-2026-45603 — Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally (7.0 HIGH)
- CVE-2026-45601 — Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally (7.0 HIGH)