CVE-2026-61869
ImageMagick vulnerability analysis and mitigation

Overview

CVE-2026-61869 is a memory leak vulnerability in the MIFF (Magick Image File Format) encoder of ImageMagick, classified as Low severity. It affects ImageMagick versions before 7.1.2-26 (7.x branch) and before 6.9.13-51 (6.9.x branch). The flaw was originally disclosed by researcher Bin-infinite and published on July 15, 2026. It carries a CVSS v3.1 base score of 2.9 (Low) and a CVSS v4.0 base score of 2.1 (Low) (GitHub Advisory, Github Advisory).

Technical details

The root cause is classified as CWE-401 (Missing Release of Memory after Effective Lifetime): when a memory allocation fails during MIFF image processing in the encoder, the code path does not properly release previously allocated memory, resulting in a leak (GitHub Advisory). Exploitation requires local access and high attack complexity, with specific deployment conditions (attack requirements: present) needed to trigger the allocation failure. An attacker would need to supply a specially crafted MIFF image file to the vulnerable encoder to trigger the faulty code path (Github Advisory). No public proof-of-concept code is known to exist at this time.

Impact

Successful exploitation results solely in an availability impact — specifically, degradation or denial of service through memory exhaustion. There is no impact on confidentiality or integrity of data. An unauthenticated local user can repeatedly trigger the memory leak by processing crafted MIFF image files, potentially exhausting available system memory and causing service degradation for other processes sharing the same host (Github Advisory, GitHub Advisory).

Mitigation and workarounds

Users should upgrade ImageMagick to version 7.1.2-26 or later (7.x branch) or 6.9.13-51 or later (6.9.x branch), where the memory leak has been patched (GitHub Advisory). If immediate patching is not feasible, restrict local access to ImageMagick's image processing functionality and limit the ability to process untrusted MIFF image files. Monitoring system memory usage for unexplained consumption during image processing operations can help detect potential exploitation attempts (Github Advisory).

Additional resources


SourceThis report was generated using AI

Related ImageMagick vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61871MEDIUM6.3
  • ImageMagick logoImageMagick
  • ImageMagick-c++
NoYesJul 15, 2026
CVE-2026-61868MEDIUM6.3
  • ImageMagick logoImageMagick
  • imagemagick
NoYesJul 15, 2026
CVE-2026-61869LOW2.1
  • ImageMagick logoImageMagick
  • ImageMagick-devel
NoYesJul 15, 2026
CVE-2026-61867LOW2.1
  • ImageMagick logoImageMagick
  • seal-ImageMagick
NoYesJul 15, 2026
CVE-2026-61872LOW2
  • ImageMagick logoImageMagick
  • ImageMagick-c++-devel
NoYesJul 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management