CVE-2026-61857

ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null check when parsing XMP profiles. Attackers can craft malicious image files with specially crafted XMP data to trigger the vulnerability and cause application crashes.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-11 14:16

Updated : 2026-07-13 22:11


NVD link : CVE-2026-61857

Mitre link : CVE-2026-61857

CVE.ORG link : CVE-2026-61857


JSON object : View

Products Affected

imagemagick

  • imagemagick
CWE
CWE-252

Unchecked Return Value