CVE-2026-66011: ImageMagick

Low severity, CVSS 3.3. EPSS: 0.1% chance of exploitation in the next 30 days.

ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options are provided. Attackers can trigger memory exhaustion by repeatedly supplying malformed command-line arguments to consume system resources.

Affected products

  • ImageMagick ImageMagick: before 7.1.2-27 (fixed in 7.1.2-27)

Published 2026-07-25. Last modified 2026-08-04.