CVE-2026-61857 MEDIUM

CVE-2026-61857: ImageMagick before 7.1.2-26 Heap Use-After-Free via XMP

Vendor Imagemagick
Product ImageMagick
Weakness CWE-252
Published July 11, 2026
Last update July 11, 2026

CVSS base score

6.3/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

What the vulnerability does

01Description

ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null check when parsing XMP profiles. Attackers can craft malicious image files with specially crafted XMP data to trigger the vulnerability and cause application crashes.

Key dates

02Disclosure timeline

July 11, 2026 CVE published