CVE-2026-61867
ImageMagick vulnerability analysis and mitigation

Overview

CVE-2026-61867 is a memory leak vulnerability in the TIFF encoder of ImageMagick that occurs when memory allocation fails during TIFF image processing. It affects all ImageMagick versions before 7.1.2-26 and was published on July 15, 2026. The vulnerability was originally disclosed via GitHub Security Advisory GHSA-jfq9-q63x-rc63 on June 26, 2026, authored by maintainer dlemstra. It carries a CVSS v3.1 base score of 2.9 (Low) and a CVSS v4.0 base score of 2.1 (Low) (GitHub Advisory, ImageMagick Advisory).

Technical details

The root cause is classified as CWE-401 (Missing Release of Memory after Effective Lifetime): when a memory allocation fails within the TIFF encoder code path, the error-handling logic does not properly free previously allocated memory before returning, resulting in a small memory leak per failed allocation. An attacker with local access can craft or supply malicious TIFF image files designed to repeatedly trigger allocation failures, causing cumulative memory exhaustion over time. Exploitation requires specific attack conditions to be present (AT:P in CVSS v4.0), contributing to the high attack complexity rating. No public proof-of-concept or technical write-up detailing the specific code location has been published (ImageMagick Advisory, GitHub Advisory).

Impact

Successful exploitation results solely in a denial-of-service condition through memory exhaustion; there is no impact on confidentiality or data integrity. An unauthenticated local attacker can cause the ImageMagick process — and potentially the host system — to become unresponsive or crash by repeatedly processing specially crafted TIFF images that trigger allocation failures. The scope is limited to the vulnerable system itself, with no lateral movement potential or data exposure risk associated with this vulnerability (GitHub Advisory, ImageMagick Advisory).

Mitigation and workarounds

The primary remediation is to upgrade ImageMagick to version 7.1.2-26 or later, which contains the fix for the memory leak in the TIFF encoder (ImageMagick Advisory). If immediate patching is not feasible, administrators should restrict local access to ImageMagick processing capabilities and validate or sanitize TIFF image inputs to prevent processing of potentially malicious files (GitHub Advisory). Given the low severity and absence of active exploitation, this vulnerability can be addressed through normal patch management cycles rather than emergency response.

Additional resources


SourceThis report was generated using AI

Related ImageMagick vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61871MEDIUM6.3
  • ImageMagick logoImageMagick
  • ImageMagick-c++
NoYesJul 15, 2026
CVE-2026-61868MEDIUM6.3
  • ImageMagick logoImageMagick
  • imagemagick
NoYesJul 15, 2026
CVE-2026-61869LOW2.1
  • ImageMagick logoImageMagick
  • ImageMagick-devel
NoYesJul 15, 2026
CVE-2026-61867LOW2.1
  • ImageMagick logoImageMagick
  • seal-ImageMagick
NoYesJul 15, 2026
CVE-2026-61872LOW2
  • ImageMagick logoImageMagick
  • ImageMagick-c++-devel
NoYesJul 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management