CVE-2026-56365
ImageMagick has a memory leak in PNG encoder when writing a MNG image
5.3
MEDIUM
CVSS 3.1
EPSS 0.28%
Description
ImageMagick before 7.1.2-19 contains a memory leak vulnerability in the PNG encoder when writing MNG images. Attackers can trigger the encoder failure condition to exhaust memory resources and cause denial of service.
How to fix CVE-2026-56365
To remediate CVE-2026-56365, upgrade the affected package to a fixed version below.
- —upgrade to 8:6.9.11.60+dfsg-1.3+deb11u15 or later
Is CVE-2026-56365 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 8:6.9.11.60+dfsg-1.3+deb11u15
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |