
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-61869 is a memory leak vulnerability in the MIFF (Magick Image File Format) encoder of ImageMagick, classified as Low severity. It affects ImageMagick versions before 7.1.2-26 (7.x branch) and before 6.9.13-51 (6.9.x branch). The flaw was originally disclosed by researcher Bin-infinite and published on July 15, 2026. It carries a CVSS v3.1 base score of 2.9 (Low) and a CVSS v4.0 base score of 2.1 (Low) (GitHub Advisory, Github Advisory).
The root cause is classified as CWE-401 (Missing Release of Memory after Effective Lifetime): when a memory allocation fails during MIFF image processing in the encoder, the code path does not properly release previously allocated memory, resulting in a leak (GitHub Advisory). Exploitation requires local access and high attack complexity, with specific deployment conditions (attack requirements: present) needed to trigger the allocation failure. An attacker would need to supply a specially crafted MIFF image file to the vulnerable encoder to trigger the faulty code path (Github Advisory). No public proof-of-concept code is known to exist at this time.
Successful exploitation results solely in an availability impact — specifically, degradation or denial of service through memory exhaustion. There is no impact on confidentiality or integrity of data. An unauthenticated local user can repeatedly trigger the memory leak by processing crafted MIFF image files, potentially exhausting available system memory and causing service degradation for other processes sharing the same host (Github Advisory, GitHub Advisory).
Users should upgrade ImageMagick to version 7.1.2-26 or later (7.x branch) or 6.9.13-51 or later (6.9.x branch), where the memory leak has been patched (GitHub Advisory). If immediate patching is not feasible, restrict local access to ImageMagick's image processing functionality and limit the ability to process untrusted MIFF image files. Monitoring system memory usage for unexplained consumption during image processing operations can help detect potential exploitation attempts (Github Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."