CVE-2026-56367: ImageMagick
Critical severity, CVSS 9.1. EPSS: 0.2% chance of exploitation in the next 30 days.
ImageMagick before 7.1.2-15 and 6.9.x before 6.9.13-40 contains an integer overflow in the PSB (PSD v2) RLE decoding path (ReadPSDChannelRLE in coders/psd.c) that causes a heap out-of-bounds read on 32-bit builds. Processing a crafted PSB file can lead to information disclosure or a crash.
Affected products
- ImageMagick ImageMagick: from 6.9.0-0, before 6.9.13-40 (fixed in 6.9.13-40); from 7.1.2-0, before 7.1.2-15 (fixed in 7.1.2-15)
Published 2026-06-21. Last modified 2026-06-26.