Low severity2.9NVD Advisory· Published Jul 15, 2026· Updated Jul 16, 2026
CVE-2026-61866
CVE-2026-61866
Description
ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attackers can trigger the memory leak by providing malformed JNG files that fail blob operations, causing resource exhaustion.
Affected products
5cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*range: <7.1.2-26
- (no CPE)range: <7.1.2-26
- Range: <7.1.2-26
- osv-coords2 versionspkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Tumbleweed
< 7.1.2.0-160000.13.1+ 1 more
- (no CPE)range: < 7.1.2.0-160000.13.1
- (no CPE)range: < 7.1.2.27-3.1
Patches
Vulnerability mechanics
References
2- github.com/ImageMagick/ImageMagick/security/advisories/GHSA-99w9-hv66-rfv7nvdVendor Advisory
- www.vulncheck.com/advisories/imagemagick-before-26-memory-leak-in-jng-encodernvdThird Party Advisory
News mentions
1- ImageMagick: 14 Vulnerabilities Including Memory Leaks and DoS Flaws Disclosed TogetherVypr Intelligence · Jul 16, 2026