MEDIUM
ImageMagick - Memory Leak in META Reader APP1JPEG Error Path
Published Jul 10, 2026
4.8
MEDIUMCVSS 4.0
EPSS 0.17%
Description
ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing specially crafted APP1JPEG image files, causing denial of service through resource exhaustion.
Affected products
-
- Version 0StatusaffectedConstraints<6.9.13-43
- Version 0StatusaffectedConstraints<7.1.2-18
- Version 6.9.13-43StatusunaffectedConstraints-
- Version 7.1.2-18StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ImageMagick | ImageMagick | unaffected |
|
OR
- < 6.9.13-43
- ≥ 7.0.0-0 · < 7.1.2-18
No data.
Red Hat Enterprise Linux 6
ImageMagick
Out of support scope
Red Hat Enterprise Linux 7
ImageMagick
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | ImageMagick | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | ImageMagick | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://access.redhat.com/security/cve/CVE-2026-56366 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2498999 Issue Tracking
- https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9r56-3gjq-hqf7 vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-56366
- https://www.cve.org/CVERecord?id=CVE-2026-56366
- https://www.vulncheck.com/advisories/imagemagick-memory-leak-in-meta-reader-app1jpeg-error-path third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-56366 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2498999 | Issue Tracking | |
| https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9r56-3gjq-hqf7 | vendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-56366 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-56366 | ||
| https://www.vulncheck.com/advisories/imagemagick-memory-leak-in-meta-reader-app1jpeg-error-path | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jul 10, 2026
Updated Jul 14, 2026
Reserved Jun 21, 2026
Link CVE-2026-56366
CISA Vulnrichment
Updated Jul 14, 2026