Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
4.8
CVE-2026-56372: ImageMagick before 7.1.2-19 allows attackers to read sensitive data
CVE-2026-56372
Summary
ImageMagick, a popular image processing software, has a security issue that could allow attackers to access sensitive information. This issue affects versions of ImageMagick prior to 7.1.2-19. To stay secure, update to the latest version of ImageMagick as soon as possible.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| imagemagick | imagemagick |
< 7.1.2-19 cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:* |
Original title
ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. An unrecognized magnify:method value triggers ...
Original description
ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. An unrecognized magnify:method value triggers an out of bounds read, potentially exposing sensitive information or causing denial of service.
nvd CVSS3.1
3.3
nvd CVSS4.0
4.8
Vulnerability type
CWE-122
Heap-based Buffer Overflow
Published: 11 Jul 2026 · Updated: 14 Jul 2026 · First seen: 11 Jul 2026