ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printed (read past the profile boundary). This behavior occurs when debug output is enabled.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-15 12:18
Updated : 2026-07-15 18:20
NVD link : CVE-2026-61862
Mitre link : CVE-2026-61862
CVE.ORG link : CVE-2026-61862
JSON object : View
Products Affected
No product.
CWE
CWE-125
Out-of-bounds Read
