CVE-2026-56366
ImageMagick: META reader memory leak in the APP1JPEG input path
6.5
MEDIUM
CVSS 3.1
EPSS 0.17%
Description
ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing specially crafted APP1JPEG image files, causing denial of service through resource exhaustion.
How to fix CVE-2026-56366
To remediate CVE-2026-56366, upgrade the affected package to a fixed version below.
- —upgrade to 8:6.9.11.60+dfsg-1.3+deb11u15 or later
Is CVE-2026-56366 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 8:6.9.11.60+dfsg-1.3+deb11u15
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |