PT-2026-57444 · Unknown · Imagemagick

·

CVE-2026-61857

·

Published

2026-07-11

·

Updated

2026-09-08

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ImageMagick versions prior to 7.1.2-26
Description A heap use-after-free issue exists due to a missing null check during the parsing of XMP profiles. An attacker can use specially crafted image files containing malicious XMP data to trigger this condition, leading to application crashes. Heap use-after-free occurs when a program continues to use a pointer after the memory it points to has been freed.
Recommendations Update to version 7.1.2-26 or later.

Exploit

Fix

Resource Exhaustion

NULL Pointer Dereference

Use After Free

Unchecked Return Value

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-61857
ECHO-5B6E-A909-DF8F
GHSA-QH5G-Q395-CX4J
JLSEC-2026-1063
OESA-2026-3057
OESA-2026-3058
OESA-2026-3059
OESA-2026-3060
OESA-2026-3061
OPENSUSE-SU-2026:11273-1
OPENSUSE-SU-2026:21391-1
SUSE-SU-2026:22829-1
SUSE-SU-2026:3192-1
SUSE-SU-2026:3193-1
SUSE-SU-2026:3194-1
SUSE-SU-2026:3219-1
USN-8739-1

Affected Products

Imagemagick