ImageMagick before 7.1.2-31 contains a heap buffer overflow vulnerability that allows attackers to overwrite heap memory by making a crafted call to the GetVirtualPixels API. Attackers can trigger the out-of-bounds heap write through crafted input to crash the server, causing a denial of service.
This CVE has been withdrawn by MITRE
MITRE marked CVE-2026-105398 as REJECTED on . It is no longer considered a valid vulnerability record. The original content below is preserved for historical reference only.
Reason given by MITRE
This CVE ID has been rejected as a duplicate.
CVE-2026-105398
✕ Withdrawn — historical dataMEDIUMPre-NVD 5.1
5.1CVSS
- CVSS v3
- 5.1
- EchelonGraph score
- Not yet assessedThis CVE record was withdrawn by its numbering authority, so there is no vulnerability to rate.
- EPSS PROB
- —
- EPSS %ILE
- —
- KEV
- —Not applicable: this CVE ID was withdrawn
Published
October 8, 2026
Last Modified
October 8, 2026
References (2)
Frequently asked(4)
What is CVE-2026-105398?
CVE-2026-105398 is a rejected CVE ID: its record was withdrawn on October 9, 2026 and no longer describes a vulnerability. Reason given: This CVE ID has been rejected as a duplicate.
When was the CVE record for CVE-2026-105398 published?
The CVE record for CVE-2026-105398 was published on October 8, 2026. EchelonGraph's copy of the record carries a last-modified date of October 8, 2026; the record at its source may have been updated since.
What is the CVSS score of CVE-2026-105398?
CVE-2026-105398 has a CVSS base score of 5.1 (a secondary CVSS source that NVD displays; NVD's own analysis pending).
How do I remediate CVE-2026-105398?
There is nothing to remediate under CVE-2026-105398: it is a rejected (withdrawn) CVE ID and no longer describes a vulnerability.