Home

Description

ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can trigger this leak by processing specially crafted images, causing memory exhaustion and denial of service.

PUBLISHED Reserved 2026-06-21 | Published 2026-06-24 | Updated 2026-06-24 | Assigner VulnCheck




MEDIUM: 6.3CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
LOW: 3.7CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

Problem types

Missing Release of Memory after Effective Lifetime

Product status

Default status
unaffected

Any version before 7.1.2-15
affected

7.1.2-15 (semver)
unaffected

Default status
unaffected

Any version before 6.9.13-40
affected

6.9.13-40 (semver)
unaffected

Credits

ylwango613 reporter

References

github.com/...Magick/security/advisories/GHSA-wfx3-6g53-9fgc (GitHub Security Advisory (GHSA-wfx3-6g53-9fgc)) vendor-advisory

www.vulncheck.com/...ck-memory-leak-in-raw-pixel-data-coders (VulnCheck Advisory: ImageMagick - Memory Leak in Raw Pixel Data Coders) third-party-advisory

cve.org (CVE-2026-56368)

nvd.nist.gov (CVE-2026-56368)

Download JSON