CVE-2026-56370: ImageMagick - Out-of-bounds Access in ConnectedComponentsImage via connected-components Artifact
ImageMagick before 7.1.2-19 contains an out-of-bounds access vulnerability in ConnectedComponentsImage() when processing connected-components artifacts with invalid indices. Attackers can trigger access violations by specifying malformed connected-components definitions via CLI, causing denial of service or potential code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56370?
CVE-2026-56370 is classified as having a low severity score of 3.3.
How do I fix CVE-2026-56370?
To fix CVE-2026-56370, you should update ImageMagick to version 7.1.2-19 or later.
What kind of vulnerability is CVE-2026-56370?
CVE-2026-56370 is an out-of-bounds access vulnerability found in the ConnectedComponentsImage function.
What can an attacker do with CVE-2026-56370?
An attacker can exploit CVE-2026-56370 to cause access violations and potentially trigger denial of service.
Which versions of ImageMagick are affected by CVE-2026-56370?
CVE-2026-56370 affects ImageMagick versions prior to 7.1.2-19.