CVE-2026-56366: ImageMagick - Memory Leak in META Reader APP1JPEG Error Path
Published Jul 10, 2026
·Updated
ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing specially crafted APP1JPEG image files, causing denial of service through resource exhaustion.
Affected Software
3 affected components
ImageMagick ImageMagick<7.1.2-18
ImageMagick ImageMagick<6.9.13-43
ImageMagick ImageMagick>=7.0.0-0<7.1.2-18
Event History
Jul 10, 2026
CVE Published
via MITRE·01:57 PM
Data Sourced
via MITRE·01:57 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-56366?
The severity of CVE-2026-56366 is medium with a score of 4.8.
2
What type of vulnerability is CVE-2026-56366?
CVE-2026-56366 is a memory leak vulnerability in the META reader of ImageMagick.
3
How can CVE-2026-56366 be exploited?
CVE-2026-56366 can be exploited by attackers providing specially crafted APP1JPEG image files to trigger a memory leak.
4
What impact does CVE-2026-56366 have on systems?
The impact of CVE-2026-56366 is denial of service due to resource exhaustion.
5
How do I fix CVE-2026-56366?
To fix CVE-2026-56366, upgrade to ImageMagick version 7.1.2-18 or later.