CVE-2026-25637

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-15, a memory leak in the ASHLAR image writer allows an attacker to exhaust process memory by providing a crafted image that results in small objects that are allocated but never freed. Version 7.1.2-15 contains a patch.
Configurations

Configuration 1 (hide)

cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:dlemstra:magick.net:*:*:*:*:*:*:*:*

History

27 Feb 2026, 14:32

Type Values Removed Values Added
References () https://github.com/ImageMagick/ImageMagick/commit/30ce0e8efbd72fd6b50ed3a10ae22f57c8901137 - () https://github.com/ImageMagick/ImageMagick/commit/30ce0e8efbd72fd6b50ed3a10ae22f57c8901137 - Patch
References () https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-gm37-qx7w-p258 - () https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-gm37-qx7w-p258 - Vendor Advisory
References () https://github.com/dlemstra/Magick.NET/releases/tag/14.10.3 - () https://github.com/dlemstra/Magick.NET/releases/tag/14.10.3 - Product, Release Notes
CPE cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
cpe:2.3:a:dlemstra:magick.net:*:*:*:*:*:*:*:*
First Time Dlemstra
Imagemagick imagemagick
Dlemstra magick.net
Imagemagick
Summary
  • (es) ImageMagick es un software libre y de código abierto utilizado para editar y manipular imágenes digitales. Antes de la versión 7.1.2-15, una fuga de memoria en el escritor de imágenes ASHLAR permite a un atacante agotar la memoria del proceso al proporcionar una imagen manipulada que resulta en objetos pequeños que se asignan pero nunca se liberan. La versión 7.1.2-15 contiene un parche.

24 Feb 2026, 01:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-24 01:16

Updated : 2026-02-27 14:32


NVD link : CVE-2026-25637

Mitre link : CVE-2026-25637

CVE.ORG link : CVE-2026-25637


JSON object : View

Products Affected

imagemagick

  • imagemagick

dlemstra

  • magick.net
CWE
CWE-401

Missing Release of Memory after Effective Lifetime