Low severity3.7NVD Advisory· Published Jun 30, 2026· Updated Jul 2, 2026
CVE-2026-56369
CVE-2026-56369
Description
ImageMagick before 7.1.2-22 contains an information disclosure vulnerability in the PasskeyEncipherImage method due to AES-CTR nonce reuse. Attackers can exploit nonce reuse in the cipher implementation to recover plaintext information from encrypted images.
Affected products
3<7.1.2.22+ 2 more
- (no CPE)range: <7.1.2.22
- cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*range: <6.9.13-47
- (no CPE)range: <7.1.2-22
Patches
Vulnerability mechanics
References
2News mentions
2- ImageMagick: Fourteen Vulnerabilities Disclosed in Batch, Affecting Multiple VersionsVypr Intelligence · Jul 2, 2026
- ImageMagick: Six Vulnerabilities Disclosed, Including File Write and Info Disclosure FlawsVypr Intelligence · Jul 1, 2026