VYPR
Low severity2.9NVD Advisory· Published Jul 15, 2026· Updated Jul 16, 2026

CVE-2026-61866

CVE-2026-61866

Description

ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attackers can trigger the memory leak by providing malformed JNG files that fail blob operations, causing resource exhaustion.

Affected products

5

Patches

Vulnerability mechanics

References

2

News mentions

1