VYPR
Low severity3.7OSV Advisory· Published Jul 10, 2026· Updated Jul 13, 2026

CVE-2026-56373

CVE-2026-56373

Description

ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when memory allocation fails. Attackers can trigger this vulnerability by processing malicious PDB files to cause crashes or write a single zero byte to freed memory.

Affected products

5

Patches

Vulnerability mechanics

References

2

News mentions

1