CVE-2026-61862
Severity CVSS v4.0:
LOW
Type:
CWE-125
Out-of-bounds Read
Publication date:
15/07/2026
Last modified:
15/07/2026
Description
ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printed (read past the profile boundary). This behavior occurs when debug output is enabled.
Impact
Base Score 4.0
2.10
Severity 4.0
LOW
Base Score 3.x
2.90
Severity 3.x
LOW



