Infinite Loop, Infinite Pain: Analyzing CVE-2026-26066 in ImageMagick



Vulnerability ID: CVE-2026-26066
CVSS Score: 6.2
Published: 2026-02-24


A logic error in ImageMagick's IPTC metadata parser allows for a trivial Denial of Service (DoS) attack. By supplying a crafted image file, an attacker can trap the processing thread in an infinite loop,...