Low severity3.7NVD Advisory· Published Jul 11, 2026· Updated Jul 13, 2026
CVE-2026-61857
CVE-2026-61857
Description
ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null check when parsing XMP profiles. Attackers can craft malicious image files with specially crafted XMP data to trigger the vulnerability and cause application crashes.
Affected products
5(expand)+ 2 more
- (no CPE)
- cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*range: <6.9.13-51
- (no CPE)range: <7.1.2-26
- osv-coords2 versionspkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Tumbleweed
< 7.1.2.0-160000.12.1+ 1 more
- (no CPE)range: < 7.1.2.0-160000.12.1
- (no CPE)range: < 7.1.2.27-2.1
Patches
Vulnerability mechanics
References
2News mentions
1- ImageMagick: Ten Vulnerabilities Disclosed Together, Affecting Memory Handling and File WritingVypr Intelligence · Jul 11, 2026