CVE-2026-61861: ImageMagick
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
ImageMagick before 7.1.2-26 contains a use-after-free vulnerability in the FormatMagickCaption method when memory allocation fails. Attackers can trigger memory allocation failures to cause a dangling pointer to reference freed memory, potentially enabling denial of service or code execution.
Affected products
- ImageMagick ImageMagick: before 6.9.13-51 (fixed in 6.9.13-51); from 7.0.0-0, before 7.1.2-26 (fixed in 7.1.2-26)
Published 2026-07-11. Last modified 2026-07-13.