CVE-2026-64685: ImageMagick
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, the BGR decoder does not check for an end-of-file in every location so a crafted image could result in an heap buffer over-read. This issue has been fixed in version 7.1.2-27.
Affected products
- ImageMagick ImageMagick: before 7.1.2-27 (fixed in 7.1.2-27)
Published 2026-07-30. Last modified 2026-08-03.