Low severity3.3OSV Advisory· Published Jul 10, 2026· Updated Jul 14, 2026
CVE-2026-56366
CVE-2026-56366
Description
ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing specially crafted APP1JPEG image files, causing denial of service through resource exhaustion.
Affected products
57.1.2-17, 7.1.2-16, 7.1.2-15, …+ 2 more
- (no CPE)range: 7.1.2-17, 7.1.2-16, 7.1.2-15, …
- cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*range: <6.9.13-43
- (no CPE)range: <7.1.2-18
- osv-coords2 versionspkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Tumbleweed
< 7.1.2.0-160000.12.1+ 1 more
- (no CPE)range: < 7.1.2.0-160000.12.1
- (no CPE)range: < 7.1.2.27-2.1
Patches
Vulnerability mechanics
References
2- github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9r56-3gjq-hqf7nvdVendor Advisory
- www.vulncheck.com/advisories/imagemagick-memory-leak-in-meta-reader-app1jpeg-error-pathnvdThird Party Advisory
News mentions
1- ImageMagick: Ten Vulnerabilities Disclosed Together, Affecting Memory Handling and File WritingVypr Intelligence · Jul 11, 2026