CVE-2026-61857
7.5
HIGH
CVSS 3.1
EPSS 0.27%
Description
ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null check when parsing XMP profiles. Attackers can craft malicious image files with specially crafted XMP data to trigger the vulnerability and cause application crashes.
How to fix CVE-2026-61857
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Debian/imagemagick—no fix listed
Is CVE-2026-61857 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |