# CVE-2026-45664

## Summary

- **CVE ID:** CVE-2026-45664
- **Severity:** MEDIUM
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
- **CWE:** CWE-400, CWE-407, CWE-674
- **Published:** Jun 10, 2026
- **Last Modified:** Sep 14, 2026

## Description

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, because of a missing check in the MNG coder it would be possible to read more images than the list limit policy would allow resulting in excessive resource use. This issue has been patched in versions 6.9.13-47 and 7.1.2-22.

## Affected Products

- ImageMagick — ImageMagick (< 6.9.13-47)
- ImageMagick — ImageMagick (< 7.1.2-22)

## References

- [CNA](https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g5mf-wqq5-vwg6)
- [redhat-SADP](https://access.redhat.com/security/cve/CVE-2026-45664)
- [redhat-SADP](https://bugzilla.redhat.com/show_bug.cgi?id=2487732)
- [redhat-SADP](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45664.json)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:32961)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.44%
- **EPSS Percentile:** 37.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._