Low severity3.3OSV Advisory· Published Jul 8, 2026· Updated Jul 9, 2026
CVE-2026-56374
CVE-2026-56374
Description
ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the FTXT encoder due to missing boundary checks when parsing ftxt:format. Remote attackers can trigger an out of bounds read by crafting malicious FTXT image files to cause denial of service or information disclosure.
Affected products
6- osv-coords3 versionspkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Tumbleweedpkg:apk/chainguard/imagemagick-6
< 7.1.2.0-160000.11.1+ 2 more
- (no CPE)range: < 7.1.2.0-160000.11.1
- (no CPE)range: < 7.1.2.27-1.1
- (no CPE)range: < 0
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*range: <7.1.2-19
- (no CPE)range: 7.1.2-18, 7.1.2-17, 7.1.2-16, …
- (no CPE)range: <7.1.2-19
Patches
Vulnerability mechanics
References
2News mentions
1- ImageMagick: Ten Vulnerabilities Disclosed Together, Affecting Memory Handling and File WritingVypr Intelligence · Jul 11, 2026