Junglewise Threat Intelligence

CVE-2026-61866: ImageMagick memory leak in JNG encoder

CVE-2026-61866 · Severity: low · CVSS 3.1 · Published 2026-07-15

Technologies: Magick.NET-Q16-OpenMP-arm64 (NuGet), Magick.NET-Q16-AnyCPU (NuGet), Magick.NET-Q16-HDRI-AnyCPU (NuGet), Magick.NET-Q8-x86 (NuGet), Magick.NET-Q8-AnyCPU (NuGet), Magick.NET-Q16-arm64 (NuGet), Magick.NET-Q16-OpenMP-x64 (NuGet), Magick.NET-Q16-HDRI-arm64 (NuGet), Magick.NET-Q16-HDRI-x86 (NuGet), Magick.NET-Q16-HDRI-x64 (NuGet), Magick.NET-Q8-OpenMP-arm64 (NuGet), Magick.NET-Q8-OpenMP-x64 (NuGet), ImageMagick, Magick.NET-Q16-x64 (NuGet), Magick.NET-Q8-arm64 (NuGet), Magick.NET-Q8-x64 (NuGet), Magick.NET-Q16-x86 (NuGet), Magick.NET-Q16-HDRI-OpenMP-arm64 (NuGet). Vendors: NuGet, ImageMagick.

Executive brief

ImageMagick is a widely used software suite for creating, editing, and converting images. A flaw in how it handles certain image files (JNG format) can cause the software to consume memory without releasing it. If exploited repeatedly, this could lead to system slowdowns or service crashes due to resource exhaustion.

Technical details

A memory leak vulnerability (CWE-401) exists in the JNG encoder of ImageMagick versions prior to 7.1.2-26. The issue occurs when the encoder fails to release allocated memory after a blob operation fails to open. An attacker can exploit this by providing malformed JNG files designed to trigger these failed operations. While the attack complexity is high and requires local access, successful exploitation results in a gradual depletion of system memory, leading to a denial-of-service (DoS) condition. The vulnerability is addressed in version 7.1.2-26.

Affected products

  • ImageMagick ImageMagick < 7.1.2-26

Timeline

  • 2026-06-26: advisory: GitHub Security Advisory published
  • 2026-07-15: disclosed: NVD publication date

References

Related threats