VYPR
Low severity3.3OSV Advisory· Published Jul 8, 2026· Updated Jul 10, 2026

CVE-2026-56362

CVE-2026-56362

Description

ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache updating image channel metadata before pixel cache memory allocation. Attackers can trigger memory and disk allocation failures to cause a heap-buffer-overflow read affecting any writer calling GetPixelIndex.

Affected products

5

Patches

Vulnerability mechanics

References

2

News mentions

1