Junglewise Threat Intelligence

ImageMagick memory leak in JNG encoder

Severity: low · CVSS 2.9 · Published 2026-07-24

Technologies: Magick.NET-Q16-OpenMP-arm64 (NuGet), Magick.NET-Q16-AnyCPU (NuGet), Magick.NET-Q16-HDRI-AnyCPU (NuGet), Magick.NET-Q8-x86 (NuGet), Magick.NET-Q8-AnyCPU (NuGet), Magick.NET-Q16-arm64 (NuGet), Magick.NET-Q16-OpenMP-x64 (NuGet), Magick.NET-Q16-HDRI-arm64 (NuGet), Magick.NET-Q16-HDRI-x86 (NuGet), Magick.NET-Q16-HDRI-x64 (NuGet), Magick.NET-Q8-OpenMP-arm64 (NuGet), ImageMagick, Dlemstra Magick.NET, Magick.NET-Q8-OpenMP-x64 (NuGet), Magick.NET-Q16-x64 (NuGet), Magick.NET-Q8-arm64 (NuGet), Magick.NET-Q8-x64 (NuGet), Magick.NET-Q16-x86 (NuGet), Magick.NET-Q16-HDRI-OpenMP-arm64 (NuGet). Vendors: NuGet, ImageMagick, Dlemstra.

Executive brief

ImageMagick is a widely used software suite for creating, editing, and converting images. A vulnerability in its JNG image encoder can cause the system to leak memory when it fails to open certain data components. If exploited repeatedly, this could lead to reduced system performance or a service outage as available memory is exhausted.

Technical details

A memory leak (CWE-401) exists in the JNG encoder of ImageMagick and its .NET wrapper, Magick.NET. The issue is triggered when the encoder fails to open a blob, resulting in allocated memory not being properly released. This is a local vulnerability with high attack complexity, as it requires specific conditions during the encoding process to trigger the failure. An attacker could potentially cause a denial-of-service condition through memory exhaustion. The issue is fixed in ImageMagick version 7.1.2-26 and Magick.NET version 14.15.0.

Affected products

  • ImageMagick ImageMagick < 7.1.2-26
  • dlemstra Magick.NET < 14.15.0

Timeline

  • 2026-06-26: disclosed
  • 2026-07-24: advisory: GitHub Advisory published

References

Related threats