Low severity3.3NVD Advisory· Published Jul 11, 2026· Updated Jul 13, 2026
CVE-2026-56372
CVE-2026-56372
Description
ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. An unrecognized magnify:method value triggers an out of bounds read, potentially exposing sensitive information or causing denial of service.
Affected products
5- osv-coords3 versionspkg:apk/chainguard/imagemagick-6pkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Tumbleweed
< 0+ 2 more
- (no CPE)range: < 0
- (no CPE)range: < 7.1.2.0-160000.12.1
- (no CPE)range: < 7.1.2.27-2.1
<7.1.2-19+ 1 more
- (no CPE)range: <7.1.2-19
- cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*range: <7.1.2-19
Patches
Vulnerability mechanics
References
2News mentions
1- ImageMagick: Ten Vulnerabilities Disclosed Together, Affecting Memory Handling and File WritingVypr Intelligence · Jul 11, 2026