CVE-2026-56374: ImageMagick - Heap Buffer Overflow in FTXT Encoder via format Parameter
Published Jul 8, 2026
·Updated
ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the FTXT encoder due to missing boundary checks when parsing ftxt:format. Remote attackers can trigger an out of bounds read by crafting malicious FTXT image files to cause denial of service or information disclosure.
Affected Software
2 affected components
ImageMagick ImageMagick<7.1.2-19
ImageMagick ImageMagick<7.1.2-19
Event History
Jul 8, 2026
CVE Published
via MITRE·01:49 PM
Data Sourced
via MITRE·01:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-56374?
The severity of CVE-2026-56374 is medium, rated at 4.8.
2
What type of vulnerability is CVE-2026-56374?
CVE-2026-56374 is a heap buffer overflow vulnerability.
3
How do I fix CVE-2026-56374?
To fix CVE-2026-56374, update ImageMagick to version 7.1.2-19 or later.
4
What can attackers achieve with CVE-2026-56374?
Attackers can exploit CVE-2026-56374 to trigger out of bounds reads that may lead to denial of service or information disclosure.
5
Which software is affected by CVE-2026-56374?
CVE-2026-56374 affects ImageMagick versions prior to 7.1.2-19.