Vulnerability record · CVE-2016-3718 · published 5 May 2016
CVE-2016-3718: ImageMagick HTTP/FTP coders allow server-side request forgery via crafted image
Redhat · Enterprise Linux Desktop
ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 mishandles the HTTP and FTP coders, letting a crafted image trigger server-side request forgery. Any application that processes untrusted images with ImageMagick can be made to issue requests to internal or attacker-chosen hosts. This is a widely deployed library, so exposure is broad wherever image conversion is exposed to user input.
Description
The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Automated analysis
high priorityIt is in CISA KEV with a very high EPSS score and public exploit code, and ImageMagick is widely deployed, though the CVSS base score is only medium.
What it is
ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 mishandles the HTTP and FTP coders, letting a crafted image trigger server-side request forgery. Any application that processes untrusted images with ImageMagick can be made to issue requests to internal or attacker-chosen hosts. This is a widely deployed library, so exposure is broad wherever image conversion is exposed to user input.
Impact
An attacker can cause the ImageMagick host to make outbound HTTP or FTP requests to arbitrary destinations, enabling internal network probing and access to services not otherwise reachable. The CVSS vector shows no confidentiality or availability impact, only high integrity impact.
Attack surface
Reached by supplying a crafted image to an ImageMagick-based processing path; the CVSS vector is local with user interaction required, so the attacker needs a user or process to open or convert the malicious file. No authentication is required by the vector.
Exploitation
CVE-2016-3718 is listed in CISA KEV with a 2021-11-03 addition and 2022-05-03 due date, and EPSS shows a 30-day probability of 0.769 at the 99.5th percentile. References include an Exploit-DB entry, indicating public exploit code exists.
What to do
- Upgrade ImageMagick to 6.9.3-10 or 7.0.1-1 or later, or apply the vendor patch referenced in the ImageMagick ChangeLog.
- Apply distribution updates from Red Hat, Ubuntu, SUSE, Oracle, Debian, Gentoo and Slackware advisories for the affected packages.
- Restrict outbound HTTP/FTP access from hosts that run ImageMagick so SSRF cannot reach internal services.
- Disable or block the HTTP and FTP coders in ImageMagick policy.xml where they are not required.
- Avoid processing untrusted images with ImageMagick on hosts with access to sensitive internal networks.
Detection
- Monitor ImageMagick processes for unexpected outbound HTTP or FTP connections to internal or unusual destinations.
- Review application logs for image conversion requests that reference remote URLs or unusual image formats.
- Alert on network traffic from image-processing servers to RFC1918 addresses or metadata endpoints.
- Check installed ImageMagick versions against the fixed 6.9.3-10 and 7.0.1-1 thresholds.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2016-3718 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "ImageMagick Server-Side Request Forgery (SSRF) Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
30 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-3718 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-3718), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.