CVE-2026-56366

ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing specially crafted APP1JPEG image files, causing denial of service through resource exhaustion.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*

History

13 Jul 2026, 15:16

Type Values Removed Values Added
CPE cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
References () https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9r56-3gjq-hqf7 - () https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9r56-3gjq-hqf7 - Vendor Advisory
References () https://www.vulncheck.com/advisories/imagemagick-memory-leak-in-meta-reader-app1jpeg-error-path - () https://www.vulncheck.com/advisories/imagemagick-memory-leak-in-meta-reader-app1jpeg-error-path - Third Party Advisory
First Time Imagemagick
Imagemagick imagemagick

10 Jul 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-10 15:16

Updated : 2026-07-14 02:16


NVD link : CVE-2026-56366

Mitre link : CVE-2026-56366

CVE.ORG link : CVE-2026-56366


JSON object : View

Products Affected

imagemagick

  • imagemagick
CWE
CWE-401

Missing Release of Memory after Effective Lifetime