Low severity3.3NVD Advisory· Published Jul 11, 2026· Updated Jul 14, 2026
CVE-2026-61465
CVE-2026-61465
Description
ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed memory allocation limit in matrix-backed operations such as -canny. An attacker can supply a crafted image that causes ImageMagick to allocate more memory than permitted by the configured policy, resulting in a denial of service.
Affected products
4cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*range: <6.9.13-51
- (no CPE)range: <7.1.2-26, <6.9.13-51
- osv-coords2 versionspkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Leap%2016.0
< 7.1.2.27-2.1+ 1 more
- (no CPE)range: < 7.1.2.27-2.1
- (no CPE)range: < 7.1.2.0-160000.12.1
Patches
Vulnerability mechanics
References
2News mentions
1- ImageMagick: Ten Vulnerabilities Disclosed Together, Affecting Memory Handling and File WritingVypr Intelligence · Jul 11, 2026