VYPR
Low severity3.3OSV Advisory· Published Jul 10, 2026· Updated Jul 14, 2026

CVE-2026-56366

CVE-2026-56366

Description

ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing specially crafted APP1JPEG image files, causing denial of service through resource exhaustion.

Affected products

5

Patches

Vulnerability mechanics

References

2

News mentions

1