ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. An unrecognized magnify:method value triggers an out of bounds read, potentially exposing sensitive information or causing denial of service.
References
| Link | Resource |
|---|---|
| https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8vfj-q2cp-5m5j | Vendor Advisory |
| https://www.vulncheck.com/advisories/imagemagick-heap-buffer-overflow-read-via-unrecognized-magnify-method | Third Party Advisory |
Configurations
History
13 Jul 2026, 22:18
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Imagemagick
Imagemagick imagemagick |
|
| CPE | cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:* | |
| References | () https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8vfj-q2cp-5m5j - Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/imagemagick-heap-buffer-overflow-read-via-unrecognized-magnify-method - Third Party Advisory |
11 Jul 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-11 14:16
Updated : 2026-07-13 22:18
NVD link : CVE-2026-56372
Mitre link : CVE-2026-56372
CVE.ORG link : CVE-2026-56372
JSON object : View
Products Affected
imagemagick
- imagemagick
CWE
CWE-122
Heap-based Buffer Overflow
