CVE-2026-56374: ImageMagick

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the FTXT encoder due to missing boundary checks when parsing ftxt:format. Remote attackers can trigger an out of bounds read by crafting malicious FTXT image files to cause denial of service or information disclosure.

Affected products

  • ImageMagick ImageMagick: before 7.1.2-19 (fixed in 7.1.2-19)

Published 2026-07-08. Last modified 2026-07-09.