Junglewise Threat Intelligence

CVE-2026-61864: ImageMagick memory leak in log colorspace transformation

CVE-2026-61864 · Severity: low · CVSS 3.1 · Published 2026-07-15

Technologies: Magick.NET-Q16-OpenMP-arm64 (NuGet), Magick.NET-Q16-AnyCPU (NuGet), Magick.NET-Q16-HDRI-AnyCPU (NuGet), ImageMagick, Magick.NET-Q8-x86 (NuGet), Magick.NET-Q8-AnyCPU (NuGet), Magick.NET-Q16-arm64 (NuGet), Magick.NET-Q16-OpenMP-x64 (NuGet), Magick.NET-Q16-HDRI-arm64 (NuGet), Magick.NET-Q16-HDRI-x86 (NuGet), Magick.NET-Q16-HDRI-x64 (NuGet), Magick.NET-Q8-OpenMP-arm64 (NuGet), Magick.NET-Q8-OpenMP-x64 (NuGet), Magick.NET-Q16-x64 (NuGet), Magick.NET-Q8-arm64 (NuGet), Magick.NET-Q8-x64 (NuGet), Magick.NET-Q16-x86 (NuGet), Magick.NET-Q16-HDRI-OpenMP-arm64 (NuGet). Vendors: NuGet, ImageMagick.

Executive brief

ImageMagick, a widely used software suite for editing and converting images, is affected by a minor memory leak. When the software fails to perform a specific color transformation (log colorspace), it fails to release a small amount of memory. While this is unlikely to cause a major system failure, repeated occurrences could theoretically lead to reduced system performance or a service crash over time.

Technical details

A memory leak vulnerability (CWE-401) exists in ImageMagick's color transformation logic. Specifically, when a transformation to the log colorspace fails, the application does not properly release allocated memory. This is a local vulnerability with high attack complexity, as it requires the attacker to trigger a specific failure condition during image processing. The primary impact is a minor degradation of availability due to resource exhaustion if the failure is triggered repeatedly. The issue is resolved in versions 7.1.2-26 and 6.9.13-51.

Affected products

  • ImageMagick ImageMagick < 7.1.2-26
  • ImageMagick ImageMagick < 6.9.13-51

Timeline

  • 2026-06-26: advisory: GitHub Security Advisory published
  • 2026-07-15: disclosed: CVE published to NVD dataset

References

Related threats