CVE-2026-93589 Overview
CVE-2026-93589 is a division-by-zero flaw in the Free Lossless Image Format (FLIF) encoder of ImageMagick. When ImageMagick processes an image containing an invalid value for ticks per second during FLIF encoding, the encoder performs a divide-by-zero operation. The resulting crash produces a denial-of-service condition in any application or service that invokes the FLIF encoder on untrusted input.
The issue affects ImageMagick versions prior to 7.1.2-31 and 6.9.13-56. Both releases contain the fix. The weakness is classified as [CWE-369] Divide By Zero.
Critical Impact
A malformed image supplied to the FLIF encoder crashes the ImageMagick process, disrupting availability for services that rely on image conversion pipelines.
Affected Products
- ImageMagick versions prior to 7.1.2-31
- ImageMagick 6.x versions prior to 6.9.13-56
- Applications and services that invoke the FLIF encoder through ImageMagick on attacker-controlled input
Discovery Timeline
- 2026-09-18 - CVE-2026-93589 published to the National Vulnerability Database (NVD)
- 2026-09-22 - Last updated in NVD database
Technical Details for CVE-2026-93589
Vulnerability Analysis
The flaw resides in the FLIF encoder path within ImageMagick. During encoding, the encoder computes a value derived from the image's ticks-per-second metadata. When the input image carries an incorrect ticks-per-second value that resolves to zero, the encoder performs an unchecked division. The process terminates with a floating-point or integer division exception, aborting the encode operation and killing the host process.
Because ImageMagick is widely embedded in web upload pipelines, content management systems, and automated conversion services, any workflow that accepts user-supplied images and converts them to FLIF can be crashed by an attacker. Repeated submissions can sustain a denial-of-service condition against the affected service. The vulnerability does not corrupt memory or expose data, and it does not permit code execution.
Root Cause
The root cause is missing input validation on the ticks-per-second value before it is used as a divisor. The encoder trusts the metadata value from the image being processed rather than verifying it is non-zero. This is a classic [CWE-369] Divide By Zero condition triggered by attacker-controlled input.
Attack Vector
Exploitation requires an attacker to deliver a crafted image file to a service that encodes images to FLIF using a vulnerable ImageMagick build. No authentication or user interaction beyond normal file submission is required for network-facing services. The impact is limited to availability of the encoding process.
No verified proof-of-concept code is publicly listed for this CVE. See the GitHub Security Advisory GHSA-4gg2-hfgh-6f5c and the VulnCheck ImageMagick Advisory for technical details.
Detection Methods for CVE-2026-93589
Indicators of Compromise
- Unexpected termination of the magick or convert binary with a floating-point exception (SIGFPE) during FLIF encoding
- Repeated crashes of image-processing workers coinciding with uploads of .flif or images destined for FLIF conversion
- Application logs showing aborted conversion jobs with source images containing anomalous ticks-per-second metadata
Detection Strategies
- Inventory hosts running ImageMagick and compare installed versions against 7.1.2-31 and 6.9.13-56
- Enable core dump collection on image-processing services and alert on SIGFPE terminations within ImageMagick call stacks
- Instrument upload pipelines to record source image hashes for any request that triggers an encoder crash
Monitoring Recommendations
- Monitor process exit codes and restart rates for containers or workers that invoke ImageMagick
- Alert on spikes in HTTP 5xx responses from image conversion endpoints
- Track error logs for divide by zero or FPE_INTDIV messages from encoding subprocesses
How to Mitigate CVE-2026-93589
Immediate Actions Required
- Upgrade ImageMagick to 7.1.2-31 or 6.9.13-56 or later across all systems
- Audit distribution packages and container base images that bundle ImageMagick and rebuild with the patched version
- Restrict or disable the FLIF encoder in policy.xml where FLIF output is not required
Patch Information
The issue is fixed in ImageMagick 7.1.2-31 and 6.9.13-56. Refer to GitHub Security Advisory GHSA-4gg2-hfgh-6f5c for the upstream fix and to the VulnCheck ImageMagick Advisory for advisory metadata.
Workarounds
- Disable the FLIF coder in ImageMagick's policy.xml until the patched version can be deployed
- Validate uploaded image metadata and reject inputs with non-positive ticks-per-second values before invoking the encoder
- Isolate image conversion in sandboxed workers with automatic restart to limit denial-of-service impact
# Example policy.xml entry to disable the FLIF coder
# Add inside the <policymap> element in /etc/ImageMagick-7/policy.xml
<policy domain="coder" rights="none" pattern="FLIF" />
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
