Heap Buffer Over-write in ImageMagick Software
CVE-2026-62343

4.7MEDIUM

Key Information:

Vendor
CVE Published:
29 July 2026

What is CVE-2026-62343?

ImageMagick, a popular open-source tool for image editing, has a security vulnerability where an invalid kernel can lead to a heap buffer over-write during morphology operations. This flaw affects versions of ImageMagick prior to 6.9.13-51 and those from 7.0.1-0 up until 7.1.2-26. The issue has been addressed in the latest software updates, and users are recommended to upgrade to secure their systems against potential exploits.

Affected Version(s)

ImageMagick < 6.9.13-51 < 6.9.13-51

ImageMagick >= 7.0.1-0, < 7.1.2-26 < 7.0.1-0, 7.1.2-26

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.