Low severity3.7NVD Advisory· Published Jul 15, 2026· Updated Jul 15, 2026
CVE-2026-61860
CVE-2026-61860
Description
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free vulnerability that occurs when freetype initialization fails: the method does not exit and continues to use memory that was already freed. This can be triggered during image processing and may lead to a denial of service.
Affected products
4- Range: <7.1.2-26 and <6.9.13-51
- Range: <7.1.2-26 and <6.9.13-51
- osv-coords2 versionspkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Tumbleweed
< 7.1.2.0-160000.13.1+ 1 more
- (no CPE)range: < 7.1.2.0-160000.13.1
- (no CPE)range: < 7.1.2.27-3.1
Patches
Vulnerability mechanics
References
2News mentions
1- ImageMagick: 14 Vulnerabilities Including Memory Leaks and DoS Flaws Disclosed TogetherVypr Intelligence · Jul 16, 2026