CVE-2026-61866

Severity CVSS v4.0:
LOW
Type:
Unavailable / Other
Publication date:
15/07/2026
Last modified:
16/07/2026

Description

ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attackers can trigger the memory leak by providing malformed JNG files that fail blob operations, causing resource exhaustion.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:* 7.1.2-26 (excluding)