CVE-2026-56378: ImageMagick

High severity, CVSS 8.2. EPSS: 0.4% chance of exploitation in the next 30 days.

ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage loop. A crafted PCD file can trigger a one-byte heap out-of-bounds read during image decoding, resulting in denial of service and potential disclosure of an adjacent heap byte.

Affected products

  • ImageMagick ImageMagick: from 6.9.0-0, before 6.9.13-40 (fixed in 6.9.13-40); from 7.1.2-0, before 7.1.2-15 (fixed in 7.1.2-15)

Published 2026-06-21. Last modified 2026-06-26.