CVE-2026-33852

7.5

MolotovCherry · Android-ImageMagick7

A memory leak vulnerability exists in MolotovCherry Android-ImageMagick7, allowing unauthenticated remote attackers to trigger a denial of service via improper memory release.

Executive summary

An unauthenticated remote denial of service vulnerability in MolotovCherry Android-ImageMagick7 poses a significant risk to system availability.

Vulnerability

The software suffers from a Missing Release of Memory after Effective Lifetime (CWE-401) flaw. Unauthenticated attackers can trigger this issue over the network, leading to exhaustion of system resources.

Business impact

The vulnerability carries a CVSS score of 7.5, reflecting its potential to cause significant service disruption. By exhausting memory, an attacker can crash the application or the underlying system, leading to downtime and potential loss of productivity. Given that the attack vector is network-based and requires no authentication, the risk to public-facing infrastructure is high.

Remediation

Immediate Action: Update the Android-ImageMagick7 component to version 7.1.2-11 or later as soon as the vendor makes the security update available.

Proactive Monitoring: Monitor system memory usage patterns and application logs for signs of sudden, unexpected resource exhaustion or repetitive service crashes.

Compensating Controls: Deploy a Web Application Firewall (WAF) or network-level traffic filtering to limit access to the affected service, potentially blocking malformed requests that trigger the memory leak.

Exploitation status

Public Exploit Available: No (exploit_available: false).

Analyst recommendation

Organizations utilizing MolotovCherry Android-ImageMagick7 must prioritize patching this vulnerability upon the release of the fixed version. Until the patch is applied, ensure that access to the affected software is strictly restricted to trusted networks to mitigate the risk of unauthenticated exploitation. Consistent monitoring of system health remains critical for early detection of potential service degradation.

More MolotovCherry CVEs

Sources

Originally found and disclosed by TITAN Team (titancaproject@gmail.com), per the CVE Program record.