CVE-2026-61871
ImageMagick vulnerability analysis and mitigation

Overview

CVE-2026-61871 is a memory leak vulnerability in ImageMagick's ICON decoder that occurs when a memory allocation fails during the processing of a crafted ICON file. Affected versions include ImageMagick before 7.1.2-26 (7.x branch) and before 6.9.13-51 (6.x branch). The vulnerability was published on July 15, 2026, with the original advisory (GHSA-h58x-r7f7-rh84) attributed to maintainer dlemstra and published June 26, 2026. It carries a CVSS v3.1 base score of 3.7 (Low) and a CVSS v4.0 base score of 6.3 (Medium) (GitHub Advisory, Github Advisory DB).

Technical details

The root cause is classified as CWE-401 (Missing Release of Memory after Effective Lifetime): when the ICON decoder encounters a memory allocation failure, it does not properly release previously allocated memory before returning, resulting in a leak. An unauthenticated attacker can exploit this remotely by submitting a specially crafted ICON file to any service or application that uses ImageMagick for image processing. Exploitation requires specific preconditions (attack requirements are rated "Present" in CVSS v4.0), meaning the target system must be in a state where allocation failures can be triggered — for example, under memory pressure. No public proof-of-concept code has been identified (GitHub Advisory, Feedly).

Impact

Successful exploitation results solely in a degradation of availability through resource exhaustion (denial of service); there is no impact on confidentiality or integrity. Repeated submission of crafted ICON files can cause progressive memory leaks, potentially exhausting system memory and causing the ImageMagick process or the hosting application to become unresponsive or crash. The scope is limited to the vulnerable system itself, with no lateral movement potential or data exposure risk identified (GitHub Advisory, Feedly).

Mitigation and workarounds

Update ImageMagick to version 7.1.2-26 or later (for the 7.x branch) or 6.9.13-51 or later (for the 6.x branch), which contain the fix for the memory leak in the ICON decoder. As a workaround, administrators can implement input validation and filtering to block processing of ICON files from untrusted sources, or disable ICON format support entirely in ImageMagick's policy configuration (/etc/ImageMagick-*/policy.xml) if the format is not required by the application (GitHub Advisory, Feedly).

Additional resources


SourceThis report was generated using AI

Related ImageMagick vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61871MEDIUM6.3
  • ImageMagick logoImageMagick
  • ImageMagick-c++
NoYesJul 15, 2026
CVE-2026-61868MEDIUM6.3
  • ImageMagick logoImageMagick
  • imagemagick
NoYesJul 15, 2026
CVE-2026-61869LOW2.1
  • ImageMagick logoImageMagick
  • ImageMagick-devel
NoYesJul 15, 2026
CVE-2026-61867LOW2.1
  • ImageMagick logoImageMagick
  • seal-ImageMagick
NoYesJul 15, 2026
CVE-2026-61872LOW2
  • ImageMagick logoImageMagick
  • ImageMagick-c++-devel
NoYesJul 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management