CVE-2026-61465: ImageMagick before 7.1.2-26 Memory Allocation Policy Bypass
ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed memory allocation limit in matrix-backed operations such as -canny. An attacker can supply a crafted image that causes ImageMagick to allocate more memory than permitted by the configured policy, resulting in a denial of service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 7.1.2-26 - Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 6.9.13-51
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61465?
The severity of CVE-2026-61465 is categorized as low, with a score of 3.3.
What is CVE-2026-61465 related to?
CVE-2026-61465 is related to a memory allocation policy bypass in ImageMagick before versions 7.1.2-26 and 6.9.13-51.
How can CVE-2026-61465 be exploited?
CVE-2026-61465 can be exploited by an attacker supplying a crafted image that forces ImageMagick to allocate more memory than allowed.
What versions of ImageMagick are affected by CVE-2026-61465?
CVE-2026-61465 affects ImageMagick versions prior to 7.1.2-26 and 6.9.13-51.
How do I fix CVE-2026-61465?
To fix CVE-2026-61465, update ImageMagick to version 7.1.2-26 or later.