CVE-2026-56365: ImageMagick

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

ImageMagick before 7.1.2-19 contains a memory leak vulnerability in the PNG encoder when writing MNG images. Attackers can trigger the encoder failure condition to exhaust memory resources and cause denial of service.

Affected products

  • ImageMagick ImageMagick: before 6.9.13-44 (fixed in 6.9.13-44); from 7.0.0-0, before 7.1.2-19 (fixed in 7.1.2-19)

Published 2026-06-30. Last modified 2026-07-02.