
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-61464 is a heap-based buffer over-write vulnerability in ImageMagick that occurs when running an X11 import operation with a crafted window title, resulting in heap memory corruption and denial of service. It affects ImageMagick versions before 7.1.2-26 (7.x branch) and before 6.9.13-51 (6.x branch). The vulnerability was published on July 15, 2026, with the original security advisory (GHSA-76q6-2p6h-xjqr) credited to reporter Kwstubbs and published by maintainer dlemstra on June 26, 2026. It carries a CVSS v3.1 base score of 1.8 (Low) and a CVSS v4.0 base score of 1.0 (Low) (GitHub Advisory, Github Advisory).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow). It is triggered when ImageMagick's X11 import functionality processes a specially crafted window title, causing a heap buffer over-write that corrupts heap memory. Exploitation requires local access, high privileges, high attack complexity, the presence of specific attack conditions, and passive user interaction — making it a difficult vulnerability to exploit in practice. No public proof-of-concept or technical write-up detailing the specific code path has been published (GitHub Advisory, bugzilla.redhat.com).
Successful exploitation results in heap memory corruption and a denial of service (application crash) of the ImageMagick process. There is no impact on confidentiality or data integrity, as the vulnerability only affects availability with a low severity rating. The scope is unchanged, meaning the impact is confined to the vulnerable ImageMagick component itself with no lateral movement or data exposure risk identified (Github Advisory, GitHub Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The CVE status is listed as "Deferred" and the NIST SSVC assessment confirms exploitation is "none." The EPSS score is approximately 0.092% (1st percentile), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory, bugzilla.redhat.com).
Update ImageMagick to version 7.1.2-26 or later (7.x branch) or 6.9.13-51 or later (6.x branch) to remediate this vulnerability. As a workaround, restrict access to ImageMagick's X11 import functionality to trusted, high-privileged users only, or disable X11 import entirely if it is not required for your use case. Vendor patches have been distributed through SUSE (SUSE-SU-2026:3194-1, SUSE-SU-2026:3219-1, SUSE-SU-2026:3395-1) and openSUSE security announcements, and Debian updates are also available (GitHub Advisory, bugzilla.redhat.com).
Red Hat has tracked this vulnerability via Bugzilla (Bug 2500894) and assigned it a low priority and severity, with no fix version listed for RHEL at time of publication. SUSE has issued multiple security update announcements addressing this CVE across its product lines. No notable researcher commentary or significant social media discussion has been observed, consistent with the low severity rating and absence of active exploitation (bugzilla.redhat.com).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."