ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing specially crafted APP1JPEG image files, causing denial of service through resource exhaustion.
References
| Link | Resource |
|---|---|
| https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9r56-3gjq-hqf7 | Vendor Advisory |
| https://www.vulncheck.com/advisories/imagemagick-memory-leak-in-meta-reader-app1jpeg-error-path | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
13 Jul 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:* | |
| References | () https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9r56-3gjq-hqf7 - Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/imagemagick-memory-leak-in-meta-reader-app1jpeg-error-path - Third Party Advisory | |
| First Time |
Imagemagick
Imagemagick imagemagick |
10 Jul 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-10 15:16
Updated : 2026-07-14 02:16
NVD link : CVE-2026-56366
Mitre link : CVE-2026-56366
CVE.ORG link : CVE-2026-56366
JSON object : View
Products Affected
imagemagick
- imagemagick
CWE
CWE-401
Missing Release of Memory after Effective Lifetime
