ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null check when parsing XMP profiles. Attackers can craft malicious image files with specially crafted XMP data to trigger the vulnerability and cause application crashes.
References
| Link | Resource |
|---|---|
| https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qh5g-q395-cx4j | Vendor Advisory |
| https://www.vulncheck.com/advisories/imagemagick-before-26-heap-use-after-free-via-xmp | Broken Link |
Configurations
Configuration 1 (hide)
|
History
13 Jul 2026, 22:11
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:* | |
| First Time |
Imagemagick
Imagemagick imagemagick |
|
| References | () https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qh5g-q395-cx4j - Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/imagemagick-before-26-heap-use-after-free-via-xmp - Broken Link |
11 Jul 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-11 14:16
Updated : 2026-07-13 22:11
NVD link : CVE-2026-61857
Mitre link : CVE-2026-61857
CVE.ORG link : CVE-2026-61857
JSON object : View
Products Affected
imagemagick
- imagemagick
CWE
CWE-252
Unchecked Return Value
