← Vulnerability feed

Vulnerability record · CVE-2016-3718 · published 5 May 2016

CVE-2016-3718: ImageMagick HTTP/FTP coders allow server-side request forgery via crafted image

Redhat · Enterprise Linux Desktop

ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 mishandles the HTTP and FTP coders, letting a crafted image trigger server-side request forgery. Any application that processes untrusted images with ImageMagick can be made to issue requests to internal or attacker-chosen hosts. This is a widely deployed library, so exposure is broad wherever image conversion is exposed to user input.

5.5 CVSS 3.1 Medium CISA KEV since 3 Nov 2021 EPSS 77% · top 0.5% CWE-918 · Server-side request forgery (SSRF)
5.5CVSS 3.1 base score, v2 4.3
77%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
30Affected product versions listed by NVD
39References
17 Jun 2026Last modified by NVD

Description

The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityIt is in CISA KEV with a very high EPSS score and public exploit code, and ImageMagick is widely deployed, though the CVSS base score is only medium.

What it is

ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 mishandles the HTTP and FTP coders, letting a crafted image trigger server-side request forgery. Any application that processes untrusted images with ImageMagick can be made to issue requests to internal or attacker-chosen hosts. This is a widely deployed library, so exposure is broad wherever image conversion is exposed to user input.

Impact

An attacker can cause the ImageMagick host to make outbound HTTP or FTP requests to arbitrary destinations, enabling internal network probing and access to services not otherwise reachable. The CVSS vector shows no confidentiality or availability impact, only high integrity impact.

Attack surface

Reached by supplying a crafted image to an ImageMagick-based processing path; the CVSS vector is local with user interaction required, so the attacker needs a user or process to open or convert the malicious file. No authentication is required by the vector.

Exploitation

CVE-2016-3718 is listed in CISA KEV with a 2021-11-03 addition and 2022-05-03 due date, and EPSS shows a 30-day probability of 0.769 at the 99.5th percentile. References include an Exploit-DB entry, indicating public exploit code exists.

What to do

  • Upgrade ImageMagick to 6.9.3-10 or 7.0.1-1 or later, or apply the vendor patch referenced in the ImageMagick ChangeLog.
  • Apply distribution updates from Red Hat, Ubuntu, SUSE, Oracle, Debian, Gentoo and Slackware advisories for the affected packages.
  • Restrict outbound HTTP/FTP access from hosts that run ImageMagick so SSRF cannot reach internal services.
  • Disable or block the HTTP and FTP coders in ImageMagick policy.xml where they are not required.
  • Avoid processing untrusted images with ImageMagick on hosts with access to sensitive internal networks.

Detection

  • Monitor ImageMagick processes for unexpected outbound HTTP or FTP connections to internal or unusual destinations.
  • Review application logs for image conversion requests that reference remote URLs or unusual image formats.
  • Alert on network traffic from image-processing servers to RFC1918 addresses or metadata endpoints.
  • Check installed ImageMagick versions against the fixed 6.9.3-10 and 7.0.1-1 thresholds.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2016-3718 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "ImageMagick Server-Side Request Forgery (SSRF) Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

30 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://git.imagemagick.org/repos/ImageMagick/blob/a01518e08c840577cabd7d3ff291a9ba735f7276/ChangeLog PatchVendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00024.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00025.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00028.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00032.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00051.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-0726.html Third Party Advisory
http://www.debian.org/security/2016/dsa-3580 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2016/05/03/18 Mailing ListThird Party Advisory
http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html Third Party Advisory
http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html Third Party Advisory
http://www.securityfocus.com/archive/1/538378/100/0/threaded Broken LinkThird Party AdvisoryVDB Entry
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.440568 Third Party Advisory
http://www.ubuntu.com/usn/USN-2990-1 Third Party Advisory
https://lists.debian.org/debian-lts-announce/2018/06/msg00009.html Mailing ListThird Party Advisory
https://security.gentoo.org/glsa/201611-21 Third Party Advisory
https://www.exploit-db.com/exploits/39767/ Third Party AdvisoryVDB Entry
https://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=29588 Vendor Advisory
https://www.imagemagick.org/script/changelog.php Release Notes
http://git.imagemagick.org/repos/ImageMagick/blob/a01518e08c840577cabd7d3ff291a9ba735f7276/ChangeLog PatchVendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00024.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00025.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00028.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00032.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00051.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-0726.html Third Party Advisory
http://www.debian.org/security/2016/dsa-3580 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2016/05/03/18 Mailing ListThird Party Advisory
http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html Third Party Advisory
http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html Third Party Advisory
http://www.securityfocus.com/archive/1/538378/100/0/threaded Broken LinkThird Party AdvisoryVDB Entry
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.440568 Third Party Advisory
http://www.ubuntu.com/usn/USN-2990-1 Third Party Advisory
https://lists.debian.org/debian-lts-announce/2018/06/msg00009.html Mailing ListThird Party Advisory
https://security.gentoo.org/glsa/201611-21 Third Party Advisory
https://www.exploit-db.com/exploits/39767/ Third Party AdvisoryVDB Entry
https://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=29588 Vendor Advisory
https://www.imagemagick.org/script/changelog.php Release Notes
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-3718 US Government Resource

Track CVE-2016-3718 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-16846SaltStack Salt API shell injection via crafted web requestsSaltStack Salt through 3002 is vulnerable to OS command injection when the SSH client is enabled and crafted web requests are sent to the Salt API. T…KEVEPSS 100%analysed9.8CVE-2020-12641Roundcube Webmail OS command injection via image conversion path settingsRoundcube Webmail before 1.4.4 passes the im_convert_path and im_identify_path configuration settings to a shell without sanitization in rcube_image.…KEVEPSS 84%analysed9.8CVE-2020-11651SaltStack Salt master authentication bypass in ClearFuncsSaltStack Salt before 2019.2.4 and 3000 before 3000.2 fails to properly validate method calls in the salt-master ClearFuncs class, allowing remote un…KEVEPSS 97%analysed9.8CVE-2020-1938Apache Tomcat AJP connector file read and JSP execution flawApache Tomcat shipped an AJP Connector enabled by default that listened on all configured IP addresses, and Tomcat treats AJP connections as more tru…KEVEPSS 99%analysed9.8CVE-2020-7247OpenSMTPD MAIL FROM command injection allows remote root code executionOpenSMTPD 6.6, as shipped in OpenBSD 6.6 and other products, mishandles input validation in smtp_mailaddr in smtp_session.c, returning an incorrect v…KEVEPSS 99%analysed9.8CVE-2019-11043PHP-FPM buffer overflow enables remote code executionPHP-FPM in certain configurations writes past allocated buffers into FCGI protocol data space, an out-of-bounds write (CWE-787, CWE-120). It affects …KEVEPSS 100%analysed9.8CVE-2019-16928Exim heap buffer overflow in string_vformat via long EHLO commandExim 4.92 through 4.92.2 contains a heap-based buffer overflow in string_vformat in string.c triggered by a long EHLO command, allowing remote code e…KEVEPSS 42%analysed9.8CVE-2019-10149Exim MTA improper recipient validation leads to remote command executionExim versions 4.87 through 4.91 fail to properly validate recipient addresses in the deliver_message() function in /src/deliver.c, allowing command i…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2016-3718), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.