Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
4.8

CVE-2026-56372: ImageMagick before 7.1.2-19 allows attackers to read sensitive data

CVE-2026-56372
Summary

ImageMagick, a popular image processing software, has a security issue that could allow attackers to access sensitive information. This issue affects versions of ImageMagick prior to 7.1.2-19. To stay secure, update to the latest version of ImageMagick as soon as possible.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
imagemagick imagemagick < 7.1.2-19
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
Original title
ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. An unrecognized magnify:method value triggers ...
Original description
ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. An unrecognized magnify:method value triggers an out of bounds read, potentially exposing sensitive information or causing denial of service.
nvd CVSS3.1 3.3
nvd CVSS4.0 4.8
Vulnerability type
CWE-122 Heap-based Buffer Overflow
Published: 11 Jul 2026 · Updated: 14 Jul 2026 · First seen: 11 Jul 2026