ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, Magick fails to check for circular references between two MVGs, leading to a stack overflow. This is a DoS vulnerability, and any situation that allows reading the mvg file will be affected. Version 7.1.2-12 fixes the issue.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68950.json",
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-674"
]
}{
"cpe": "cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "7.1.2-12"
}
]
}[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"213328673569520581352047133926445811912",
"3556326905722506442906296695240234989",
"487170900548079139867774542807118714",
"57863189631568782342065078741831770119"
]
},
"signature_version": "v1",
"source": "https://github.com/imagemagick/imagemagick/commit/204718c2211903949dcfc0df8e65ed066b008dec",
"signature_type": "Line",
"target": {
"file": "MagickCore/draw.c"
},
"id": "CVE-2025-68950-6231e2a4",
"deprecated": false
},
{
"digest": {
"length": 12304.0,
"function_hash": "319136154103146613798415827121954676538"
},
"signature_version": "v1",
"source": "https://github.com/imagemagick/imagemagick/commit/204718c2211903949dcfc0df8e65ed066b008dec",
"signature_type": "Function",
"target": {
"function": "DrawPrimitive",
"file": "MagickCore/draw.c"
},
"id": "CVE-2025-68950-f240fd38",
"deprecated": false
}
]
"2026-07-22T00:20:47Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68950.json"