CVE-2026-56368

ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can trigger this leak by processing specially crafted images, causing memory exhaustion and denial of service.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*

History

26 Jun 2026, 21:51

Type Values Removed Values Added
References () https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wfx3-6g53-9fgc - () https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wfx3-6g53-9fgc - Vendor Advisory
References () https://www.vulncheck.com/advisories/imagemagick-memory-leak-in-raw-pixel-data-coders - () https://www.vulncheck.com/advisories/imagemagick-memory-leak-in-raw-pixel-data-coders - Third Party Advisory
CPE cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
First Time Imagemagick
Imagemagick imagemagick

24 Jun 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-24 13:16

Updated : 2026-06-26 21:51


NVD link : CVE-2026-56368

Mitre link : CVE-2026-56368

CVE.ORG link : CVE-2026-56368


JSON object : View

Products Affected

imagemagick

  • imagemagick
CWE
CWE-401

Missing Release of Memory after Effective Lifetime