Medium severity5.9NVD Advisory· Published Jul 1, 2026· Updated Jul 2, 2026
CVE-2026-55577
CVE-2026-55577
Description
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.
Affected products
4<7.1.2-26+ 2 more
- (no CPE)range: <7.1.2-26
- cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*range: <6.9.13-51
- (no CPE)range: <6.9.13-51, <7.1.2-26
Patches
Vulnerability mechanics
References
1News mentions
1- ImageMagick: Fourteen Vulnerabilities Disclosed in Batch, Affecting Multiple VersionsVypr Intelligence · Jul 2, 2026