CVE-2026-61866

ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attackers can trigger the memory leak by providing malformed JNG files that fail blob operations, causing resource exhaustion.
Configurations

Configuration 1 (hide)

cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*

History

16 Jul 2026, 03:01

Type Values Removed Values Added
CPE cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
First Time Imagemagick
Imagemagick imagemagick
References () https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-99w9-hv66-rfv7 - () https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-99w9-hv66-rfv7 - Vendor Advisory
References () https://www.vulncheck.com/advisories/imagemagick-before-26-memory-leak-in-jng-encoder - () https://www.vulncheck.com/advisories/imagemagick-before-26-memory-leak-in-jng-encoder - Third Party Advisory

15 Jul 2026, 12:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-15 12:18

Updated : 2026-07-16 03:01


NVD link : CVE-2026-61866

Mitre link : CVE-2026-61866

CVE.ORG link : CVE-2026-61866


JSON object : View

Products Affected

imagemagick

  • imagemagick
CWE
CWE-401

Missing Release of Memory after Effective Lifetime