
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-61870 is a memory leak vulnerability in ImageMagick's VIFF (Visualization Image File Format) encoder that can be exploited to cause denial of service. When memory allocation fails during VIFF image encoding, allocated memory is not properly released, allowing attackers to exhaust available system memory by processing specially crafted VIFF images. The vulnerability affects ImageMagick versions before 7.1.2-26 (7.x branch) and before 6.9.13-51 (6.x branch). It was published on July 11, 2026, with the underlying advisory (GHSA-m596-67p7-69wh) originally published June 26, 2026. The CVSS v3.1 base score is 7.5 (High) per NVD, though the ImageMagick project rates it Low (2.9 CVSS v3 / 2.1 CVSS v4) (GitHub Advisory, ImageMagick Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-401 (Missing Release of Memory after Effective Lifetime) and CWE-772 (Missing Release of Resource after Effective Lifetime). In the VIFF encoder code path, when a memory allocation call fails, the error-handling logic does not properly free previously allocated memory before returning, resulting in a memory leak. An attacker can repeatedly trigger this condition by submitting specially crafted VIFF image files to any service or application that processes images via ImageMagick, gradually exhausting the host's available memory. The attack requires local access or the ability to supply image files to an ImageMagick-processing pipeline, and exploitation complexity is rated High due to the prerequisite conditions needed to reliably trigger allocation failures (ImageMagick Advisory, GitHub Advisory).
Successful exploitation results in a denial-of-service condition through memory exhaustion, with no impact on confidentiality or data integrity. An attacker who can supply crafted VIFF images to an ImageMagick-processing service can degrade or crash that service, potentially affecting availability of dependent applications such as web platforms, content management systems, or image processing pipelines. There is no evidence of lateral movement potential or data exposure risk associated with this vulnerability (Red Hat Bugzilla, GitHub Advisory).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.10–0.19%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD's SSVC assessment classifies exploitation as "none" with the attack rated as non-automatable. No threat actor attribution has been reported (GitHub Advisory, ImageMagick Advisory).
Update ImageMagick to version 7.1.2-26 or later (for the 7.x branch) or 6.9.13-51 or later (for the 6.x branch) to remediate the vulnerability. SUSE has released security updates (SUSE-SU-2026:3192-1, SUSE-SU-2026:3201-1, SUSE-SU-2026:3219-1) addressing this and related ImageMagick issues. As a workaround where patching is not immediately possible, restrict ImageMagick from processing untrusted VIFF image files, implement input validation to reject VIFF format files, or use ImageMagick's policy.xml to disable the VIFF coder. Monitor system memory usage during image processing operations for anomalous consumption (ImageMagick Advisory, SUSE Update).
The vulnerability received routine coverage from vulnerability tracking platforms and Linux distribution security teams. SUSE issued multiple security advisories and updates addressing the flaw across their product lines. Red Hat opened a tracking bug and classified the severity as Low. No notable researcher commentary or significant community discussion beyond standard vulnerability disclosure channels has been observed (Red Hat Bugzilla, SUSE Update).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."