Junglewise Threat Intelligence

CVE-2026-56371: ImageMagick memory leak in TXT file processing via texture attribute

CVE-2026-56371 · Severity: low · CVSS 3.1 · Published 2026-06-23

Technologies: ImageMagick, Magick.NET-Q16-OpenMP-arm64 (NuGet), Magick.NET-Q16-AnyCPU (NuGet), Magick.NET-Q16-HDRI-AnyCPU (NuGet), Magick.NET-Q8-x86 (NuGet), Magick.NET-Q8-AnyCPU (NuGet), Magick.NET-Q16-arm64 (NuGet), Magick.NET-Q16-OpenMP-x64 (NuGet), Magick.NET-Q16-HDRI-OpenMP-x64 (NuGet), Magick.NET-Q16-OpenMP-x86 (NuGet), Magick.NET-Q16-HDRI-arm64 (NuGet), Magick.NET-Q16-HDRI-x86 (NuGet), Magick.NET-Q16-HDRI-x64 (NuGet), Magick.NET-Q8-OpenMP-arm64 (NuGet), Magick.NET-Q8-OpenMP-x64 (NuGet), Magick.NET-Q16-x64 (NuGet), Magick.NET-Q8-arm64 (NuGet), Magick.NET-Q8-x64 (NuGet), Magick.NET-Q16-x86 (NuGet), Magick.NET-Q16-HDRI-OpenMP-arm64 (NuGet). Vendors: ImageMagick, NuGet.

Executive brief

ImageMagick is a widely used software suite for displaying, converting, and editing image files. A flaw in how it handles certain text-based image files can cause the system to leak memory. While this specific issue is rated as having no immediate security impact on system availability or data, repeated processing of specially crafted files could theoretically lead to increased memory consumption over time.

Technical details

A memory leak (CWE-401) exists in ImageMagick's coders/txt.c. When a TXT file specifies a texture attribute, the software allocates a texture object via ReadImage. If a subsequent call to GetTypeMetrics fails (returning MagickFalse), the function exits without releasing the allocated texture object. This allows an attacker to cause a minor memory leak by providing a crafted TXT file. The vulnerability is reachable over the network without authentication or user interaction, though it has been assigned a CVSS score of 0.0 as it does not currently pose a significant threat to availability, integrity, or confidentiality. The issue is resolved in versions 7.1.2-15 and 6.9.13-40.

Affected products

  • ImageMagick ImageMagick < 7.1.2-15, < 6.9.13-40

Timeline

  • 2026-02-23: advisory: GitHub Security Advisory published
  • 2026-06-23: disclosed: NVD publication date

References

Related threats