VYPR
Low severity3.3NVD Advisory· Published Jun 30, 2026· Updated Jul 2, 2026

CVE-2026-56361

CVE-2026-56361

Description

ImageMagick before 7.1.2-19 contains an off-by-one error in morphology validation allowing out-of-bounds heap buffer reads. Attackers can trigger heap buffer overflow by providing incorrect morphology parameters causing single pixel memory access violations.

Affected products

4

Patches

Vulnerability mechanics

References

2

News mentions

2