VYPR
Low severity3.7NVD Advisory· Published Jun 30, 2026· Updated Jul 2, 2026

CVE-2026-56369

CVE-2026-56369

Description

ImageMagick before 7.1.2-22 contains an information disclosure vulnerability in the PasskeyEncipherImage method due to AES-CTR nonce reuse. Attackers can exploit nonce reuse in the cipher implementation to recover plaintext information from encrypted images.

Affected products

3
  • ImageMagick/Imagemagickinferred3 versions
    <7.1.2.22+ 2 more
    • (no CPE)range: <7.1.2.22
    • cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*range: <6.9.13-47
    • (no CPE)range: <7.1.2-22

Patches

Vulnerability mechanics

References

2

News mentions

2