CVE-2026-61870: ImageMagick before 7.1.2-26 Memory Leak via VIFF Encoder
Published Jul 11, 2026
·Updated
ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF encoder when memory allocation fails. Attackers can trigger allocation failures by processing specially crafted VIFF images to exhaust available memory and cause denial of service.
Affected Software
3 affected components
ImageMagick ImageMagick<7.1.2-26
ImageMagick ImageMagick<6.9.13-51
ImageMagick ImageMagick>=7.0.0-0<7.1.2-26
Event History
Jul 11, 2026
CVE Published
via MITRE·01:01 PM
Data Sourced
via MITRE·01:01 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-61870?
The severity of CVE-2026-61870 is classified as low with a score of 2.9.
2
How do I fix CVE-2026-61870?
To mitigate CVE-2026-61870, upgrade ImageMagick to version 7.1.2-26 or later.
3
What does CVE-2026-61870 affect?
CVE-2026-61870 affects ImageMagick versions prior to 7.1.2-26.
4
What type of vulnerability is CVE-2026-61870?
CVE-2026-61870 is a memory leak vulnerability in the VIFF encoder of ImageMagick.
5
How can CVE-2026-61870 be exploited?
CVE-2026-61870 can be exploited by attackers through specially crafted VIFF images that trigger memory allocation failures.