CVE-2026-61464: ImageMagick before 7.1.2-26 Heap Buffer Over-Write via X11
Published Jul 15, 2026
·Updated
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer over-write vulnerability that occurs when running an X11 import with a crafted window title, which can result in heap memory corruption and denial of service.
Affected Software
2 affected components
ImageMagick ImageMagick<7.1.2-26
ImageMagick ImageMagick<6.9.13-51
Event History
Jul 15, 2026
CVE Published
via MITRE·11:25 AM
Data Sourced
via MITRE·11:25 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-61464?
The severity of CVE-2026-61464 is rated as low.
2
How do I fix CVE-2026-61464?
To fix CVE-2026-61464, update ImageMagick to version 7.1.2-26 or later.
3
What is the impact of CVE-2026-61464?
CVE-2026-61464 can lead to heap memory corruption and potential denial of service conditions.
4
What versions of ImageMagick are affected by CVE-2026-61464?
ImageMagick versions before 7.1.2-26 and 6.9.13-51 are affected by CVE-2026-61464.
5
How does CVE-2026-61464 occur?
CVE-2026-61464 occurs when running an X11 import with a specially crafted window title.