Skip to main content
Vulnerability Database/CVE-2026-93589

CVE-2026-93589: ImageMagick FLIF Encoder DoS Vulnerability

CVE-2026-93589 is a division-by-zero denial of service flaw in ImageMagick FLIF encoder that crashes the application when processing malicious images. This post covers technical details, affected versions, and mitigation.

Published:

CVE-2026-93589 Overview

CVE-2026-93589 is a division-by-zero flaw in the Free Lossless Image Format (FLIF) encoder of ImageMagick. When ImageMagick processes an image containing an invalid value for ticks per second during FLIF encoding, the encoder performs a divide-by-zero operation. The resulting crash produces a denial-of-service condition in any application or service that invokes the FLIF encoder on untrusted input.

The issue affects ImageMagick versions prior to 7.1.2-31 and 6.9.13-56. Both releases contain the fix. The weakness is classified as [CWE-369] Divide By Zero.

Critical Impact

A malformed image supplied to the FLIF encoder crashes the ImageMagick process, disrupting availability for services that rely on image conversion pipelines.

Affected Products

  • ImageMagick versions prior to 7.1.2-31
  • ImageMagick 6.x versions prior to 6.9.13-56
  • Applications and services that invoke the FLIF encoder through ImageMagick on attacker-controlled input

Discovery Timeline

  • 2026-09-18 - CVE-2026-93589 published to the National Vulnerability Database (NVD)
  • 2026-09-22 - Last updated in NVD database

Technical Details for CVE-2026-93589

Vulnerability Analysis

The flaw resides in the FLIF encoder path within ImageMagick. During encoding, the encoder computes a value derived from the image's ticks-per-second metadata. When the input image carries an incorrect ticks-per-second value that resolves to zero, the encoder performs an unchecked division. The process terminates with a floating-point or integer division exception, aborting the encode operation and killing the host process.

Because ImageMagick is widely embedded in web upload pipelines, content management systems, and automated conversion services, any workflow that accepts user-supplied images and converts them to FLIF can be crashed by an attacker. Repeated submissions can sustain a denial-of-service condition against the affected service. The vulnerability does not corrupt memory or expose data, and it does not permit code execution.

Root Cause

The root cause is missing input validation on the ticks-per-second value before it is used as a divisor. The encoder trusts the metadata value from the image being processed rather than verifying it is non-zero. This is a classic [CWE-369] Divide By Zero condition triggered by attacker-controlled input.

Attack Vector

Exploitation requires an attacker to deliver a crafted image file to a service that encodes images to FLIF using a vulnerable ImageMagick build. No authentication or user interaction beyond normal file submission is required for network-facing services. The impact is limited to availability of the encoding process.

No verified proof-of-concept code is publicly listed for this CVE. See the GitHub Security Advisory GHSA-4gg2-hfgh-6f5c and the VulnCheck ImageMagick Advisory for technical details.

Detection Methods for CVE-2026-93589

Indicators of Compromise

  • Unexpected termination of the magick or convert binary with a floating-point exception (SIGFPE) during FLIF encoding
  • Repeated crashes of image-processing workers coinciding with uploads of .flif or images destined for FLIF conversion
  • Application logs showing aborted conversion jobs with source images containing anomalous ticks-per-second metadata

Detection Strategies

  • Inventory hosts running ImageMagick and compare installed versions against 7.1.2-31 and 6.9.13-56
  • Enable core dump collection on image-processing services and alert on SIGFPE terminations within ImageMagick call stacks
  • Instrument upload pipelines to record source image hashes for any request that triggers an encoder crash

Monitoring Recommendations

  • Monitor process exit codes and restart rates for containers or workers that invoke ImageMagick
  • Alert on spikes in HTTP 5xx responses from image conversion endpoints
  • Track error logs for divide by zero or FPE_INTDIV messages from encoding subprocesses

How to Mitigate CVE-2026-93589

Immediate Actions Required

  • Upgrade ImageMagick to 7.1.2-31 or 6.9.13-56 or later across all systems
  • Audit distribution packages and container base images that bundle ImageMagick and rebuild with the patched version
  • Restrict or disable the FLIF encoder in policy.xml where FLIF output is not required

Patch Information

The issue is fixed in ImageMagick 7.1.2-31 and 6.9.13-56. Refer to GitHub Security Advisory GHSA-4gg2-hfgh-6f5c for the upstream fix and to the VulnCheck ImageMagick Advisory for advisory metadata.

Workarounds

  • Disable the FLIF coder in ImageMagick's policy.xml until the patched version can be deployed
  • Validate uploaded image metadata and reject inputs with non-positive ticks-per-second values before invoking the encoder
  • Isolate image conversion in sandboxed workers with automatic restart to limit denial-of-service impact
bash
# Example policy.xml entry to disable the FLIF coder
# Add inside the <policymap> element in /etc/ImageMagick-7/policy.xml
<policy domain="coder" rights="none" pattern="FLIF" />

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.