CVE-2026-56370: ImageMagick
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
ImageMagick before 7.1.2-19 contains an out-of-bounds access vulnerability in ConnectedComponentsImage() when processing connected-components artifacts with invalid indices. Attackers can trigger access violations by specifying malformed connected-components definitions via CLI, causing denial of service or potential code execution.
Affected products
- ImageMagick ImageMagick: before 6.9.13-44 (fixed in 6.9.13-44); from 7.0.0-0, before 7.1.2-19 (fixed in 7.1.2-19)
Published 2026-06-24. Last modified 2026-06-26.