
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-56363 is a division-by-zero vulnerability in ImageMagick's binomial kernel processing that allows local attackers to cause a denial of service (application crash). It affects ImageMagick versions before 7.1.2-22 (7.x branch) and before 6.9.13-47 (6.x branch). The vulnerability was published on June 30, 2026, with a patch released in ImageMagick 7.1.2-22 and 6.9.13-47. It carries a CVSS v3.1 base score of 3.3 (Low) and a CVSS v4.0 base score of 4.8 (Medium) (GitHub Advisory, Github Advisory).
The root cause is an integer overflow (CWE-190) combined with a divide-by-zero condition (CWE-369) in the binomial kernel processing code. When a user supplies an excessively large binomial kernel value, the resulting integer overflow causes a downstream calculation to produce a zero divisor, triggering a division-by-zero error and crashing the application. Exploitation requires local access and user interaction — specifically, a victim must process a maliciously crafted input through ImageMagick. The vulnerability was reported by researcher '007bsd' (GitHub Advisory).
Successful exploitation results in an application crash, causing a denial of service limited to the availability of the ImageMagick process. There is no impact on confidentiality or data integrity, and the scope is unchanged — meaning the crash does not propagate beyond the affected ImageMagick instance. The impact is particularly relevant in environments where ImageMagick is used as a backend image processing service, where repeated crashes could disrupt service availability (Github Advisory, GitHub Advisory).
SIGFPE signals).Upgrade ImageMagick to version 7.1.2-22 or later (7.x branch) or 6.9.13-47 or later (6.x branch) to remediate the vulnerability. As a workaround, implement input validation to restrict the range of binomial kernel values accepted before passing them to ImageMagick. Linux distribution users should apply vendor-provided security updates; patches have been issued for Debian and SUSE (GitHub Advisory, SUSE Advisory).
The vulnerability was assigned low-to-moderate severity by the ImageMagick maintainers and patched promptly. Linux distribution vendors including Debian and SUSE issued security update announcements incorporating the fix. No significant researcher commentary or broader media coverage has been observed beyond standard vulnerability tracking and distribution security advisories.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."