CVE-2026-22770: ImageMagick

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

ImageMagick is free and open-source software used for editing and manipulating digital images. The BilateralBlurImage method will allocate a set of double buffers inside AcquireBilateralTLS. But, in versions prior to 7.1.2-13, the last element in the set is not properly initialized. This will result in a release of an invalid pointer inside DestroyBilateralTLS when the memory allocation fails. Version 7.1.2-13 contains a patch for the issue.

Affected products

  • ImageMagick ImageMagick: before 7.1.2-13 (fixed in 7.1.2-13)

Published 2026-01-20. Last modified 2026-06-17.