CVE-2026-56366: ImageMagick
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing specially crafted APP1JPEG image files, causing denial of service through resource exhaustion.
Affected products
- ImageMagick ImageMagick: before 6.9.13-43 (fixed in 6.9.13-43); from 7.0.0-0, before 7.1.2-18 (fixed in 7.1.2-18)
Published 2026-07-10. Last modified 2026-07-14.