CVE-2026-56373: ImageMagick

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when memory allocation fails. Attackers can trigger this vulnerability by processing malicious PDB files to cause crashes or write a single zero byte to freed memory.

Affected products

  • ImageMagick ImageMagick: before 6.9.13-40 (fixed in 6.9.13-40); from 7.0.0-0, before 7.1.2-15 (fixed in 7.1.2-15)

Published 2026-07-10. Last modified 2026-07-13.