CVE-2026-66011

ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options are provided. Attackers can trigger memory exhaustion by repeatedly supplying malformed command-line arguments to consume system resources.
Configurations

Configuration 1 (hide)

cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*

History

04 Aug 2026, 13:52

Type Values Removed Values Added
CPE cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
References () https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-cvhv-g4rq-3hmw - () https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-cvhv-g4rq-3hmw - Vendor Advisory
References () https://www.vulncheck.com/advisories/imagemagick-before-27-memory-leak-via-invalid-cli-options - () https://www.vulncheck.com/advisories/imagemagick-before-27-memory-leak-via-invalid-cli-options - Third Party Advisory
First Time Imagemagick
Imagemagick imagemagick

25 Jul 2026, 11:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-25 11:17

Updated : 2026-08-04 13:52


NVD link : CVE-2026-66011

Mitre link : CVE-2026-66011

CVE.ORG link : CVE-2026-66011


JSON object : View

Products Affected

imagemagick

  • imagemagick
CWE
CWE-401

Missing Release of Memory after Effective Lifetime