CVE-2026-56361: ImageMagick
High severity, CVSS 7.1. EPSS: 0.1% chance of exploitation in the next 30 days.
ImageMagick before 7.1.2-19 contains an off-by-one error in morphology validation allowing out-of-bounds heap buffer reads. Attackers can trigger heap buffer overflow by providing incorrect morphology parameters causing single pixel memory access violations.
Affected products
- ImageMagick ImageMagick: before 6.9.13-44 (fixed in 6.9.13-44); from 7.0.0-0, before 7.1.2-19 (fixed in 7.1.2-19)
Published 2026-06-30. Last modified 2026-07-02.