CVE-2026-56361: ImageMagick

High severity, CVSS 7.1. EPSS: 0.1% chance of exploitation in the next 30 days.

ImageMagick before 7.1.2-19 contains an off-by-one error in morphology validation allowing out-of-bounds heap buffer reads. Attackers can trigger heap buffer overflow by providing incorrect morphology parameters causing single pixel memory access violations.

Affected products

  • ImageMagick ImageMagick: before 6.9.13-44 (fixed in 6.9.13-44); from 7.0.0-0, before 7.1.2-19 (fixed in 7.1.2-19)

Published 2026-06-30. Last modified 2026-07-02.