CVE-2026-102635 UNKNOWN

CVE-2026-102635

Published: 2026-09-29

Description

ImageMagick versions before 7.1.2-32 and 6.9.13-57 contain uninitialized heap memory disclosure in the GIF decoder's application extension handler in coders/gif.c. Attackers can craft malicious GIF files that cause the number parser to read uninitialized heap memory and store contents as image metadata, disclosing sensitive heap information.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…