Junglewise Threat Intelligence

CVE-2026-61861: ImageMagick use-after-free in FormatMagickCaption

CVE-2026-61861 · Severity: low · CVSS 3.7 · Published 2026-07-11

Technologies: Magick.NET-Q16-OpenMP-arm64 (NuGet), Magick.NET-Q16-AnyCPU (NuGet), Magick.NET-Q16-HDRI-AnyCPU (NuGet), Magick.NET-Q8-x86 (NuGet), Magick.NET-Q8-AnyCPU (NuGet), Magick.NET-Q16-arm64 (NuGet), Magick.NET-Q16-OpenMP-x64 (NuGet), Magick.NET-Q16-HDRI-arm64 (NuGet), Magick.NET-Q16-HDRI-x86 (NuGet), Magick.NET-Q16-HDRI-x64 (NuGet), Magick.NET-Q8-OpenMP-arm64 (NuGet), Magick.NET-Q8-OpenMP-x64 (NuGet), ImageMagick, Magick.NET-Q16-x64 (NuGet), Magick.NET-Q8-arm64 (NuGet), Magick.NET-Q8-x64 (NuGet), Magick.NET-Q16-x86 (NuGet), Magick.NET-Q16-HDRI-OpenMP-arm64 (NuGet). Vendors: NuGet, ImageMagick.

Executive brief

ImageMagick, a widely used software suite for displaying and editing images, contains a flaw in how it handles memory when processing image captions. If the software runs out of memory while performing this specific task, it may continue to reference data that has already been cleared, which can lead to a program crash or service instability. This could be used by an attacker to cause a denial of service, though the complexity required to trigger the bug makes it a lower-risk issue.

Technical details

A use-after-free (UAF) vulnerability exists in ImageMagick's FormatMagickCaption method. The flaw is triggered when a memory allocation failure occurs, leaving a dangling pointer that references previously freed memory. An attacker could potentially exploit this by forcing memory exhaustion or providing specific inputs that trigger allocation failures, leading to a crash (denial of service) or potentially arbitrary code execution. The vulnerability is considered low severity due to the high complexity required to reliably trigger the specific memory failure state. The issue is addressed in versions 7.1.2-26 and 6.9.13-51.

Affected products

  • ImageMagick ImageMagick < 7.1.2-26
  • ImageMagick ImageMagick < 6.9.13-51

Timeline

  • 2026-06-26: advisory: GitHub Security Advisory published
  • 2026-07-11: disclosed: NVD publication date

References

Related threats