CVE-2026-56372: ImageMagick - Heap Buffer Overflow Read via Unrecognized Magnify Method
Published Jul 11, 2026
·Updated
ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. An unrecognized magnify:method value triggers an out of bounds read, potentially exposing sensitive information or causing denial of service.
Affected Software
2 affected components
ImageMagick ImageMagick<7.1.2-19
ImageMagick ImageMagick<7.1.2-19
Event History
Jul 11, 2026
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-56372?
CVE-2026-56372 has a medium severity rating of 4.8.
2
What type of vulnerability is CVE-2026-56372?
CVE-2026-56372 is a heap buffer overflow vulnerability found in ImageMagick.
3
How do I fix CVE-2026-56372?
To fix CVE-2026-56372, update ImageMagick to version 7.1.2-19 or later.
4
What impact does CVE-2026-56372 have on systems?
CVE-2026-56372 can potentially expose sensitive information or cause denial of service.
5
Which software is affected by CVE-2026-56372?
CVE-2026-56372 affects ImageMagick versions prior to 7.1.2-19.