CVE-2026-33856
7.5MolotovCherry · Android-ImageMagick7
A memory leak vulnerability exists in MolotovCherry Android-ImageMagick7, allowing an unauthenticated attacker to cause a denial of service via memory exhaustion.
Executive summary
A memory leak vulnerability in MolotovCherry Android-ImageMagick7 allows unauthenticated attackers to trigger a denial of service through resource exhaustion.
Vulnerability
This is a memory leak vulnerability (CWE-401) where the application fails to release memory after its effective lifetime, which can be triggered by an unauthenticated attacker over the network.
Business impact
The vulnerability carries a CVSS score of 7.5, reflecting a significant risk to service availability. By repeatedly triggering this memory leak, an attacker can exhaust system resources, leading to application crashes or complete service interruption, which may cause operational downtime and impact business continuity.
Remediation
Immediate Action: Update the Android-ImageMagick7 library to version 7.1.2-11 or later to resolve the memory management defect.
Proactive Monitoring: Monitor system memory usage and application crash logs for sudden, unexplained spikes or recurring failures consistent with resource exhaustion.
Compensating Controls: Deploy a Web Application Firewall (WAF) or an API gateway to rate-limit requests to the image processing service, which can slow down the speed at which an attacker can exhaust memory.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the high CVSS score and the potential for service disruption, organizations should prioritize updating the Android-ImageMagick7 component to the fixed version. While there is no current evidence of active exploitation, the accessibility of this flaw to unauthenticated remote attackers necessitates prompt remediation to maintain system stability and availability.
More MolotovCherry CVEs
Sources
Originally found and disclosed by TITAN Team (titancaproject@gmail.com), per the CVE Program record.