PT-2026-60152 · Unknown · Imagemagick

·

CVE-2026-61862

·

Published

2026-07-15

·

Updated

2026-07-30

CVSS v3.1

2.9

Low

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions ImageMagick versions prior to 7.1.2-26 ImageMagick versions prior to 6.9.13-51
Description An information disclosure issue exists when using the identify command to display a profile. If the profile value is not printable and debug output is enabled, the system may read past the profile boundary and print a single byte from the end of the profile.
Recommendations Update ImageMagick to version 7.1.2-26 or later. Update ImageMagick to version 6.9.13-51 or later. Disable debug output to prevent the disclosure of memory bytes.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61862
ECHO-D2CD-4E93-4618
GHSA-HWF3-R46V-5GGX
JLSEC-2026-1068
OPENSUSE-SU-2026:11310-1
OPENSUSE-SU-2026:21426-1
SUSE-SU-2026:22861-1
SUSE-SU-2026:3192-1
SUSE-SU-2026:3193-1
SUSE-SU-2026:3194-1
SUSE-SU-2026:3219-1

Affected Products

Imagemagick