Memory Leak Vulnerability in ImageMagick Software by ImageMagick Group
CVE-2026-56375

4.8MEDIUM

Key Information:

Vendor
CVE Published:
15 July 2026

What is CVE-2026-56375?

ImageMagick versions up to 7.1.2-18 are affected by a memory leak vulnerability within the ASHLAR coder. When certain actions fail, this vulnerability can be exploited by attackers to trigger the failure repeatedly, leading to excessive memory consumption. Ultimately, this can result in a denial of service, as the application's resources become depleted. It is essential for users of ImageMagick to assess their exposure to this vulnerability and implement necessary mitigations.

Affected Version(s)

ImageMagick 0 <= 7.1.2-18

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

unbengable12
.