Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

ImageMagick — Vulnerabilities & Security Advisories 227

All 227 CVE vulnerabilities found in ImageMagick, with AI-generated Chinese analysis, references, and POCs.

This vulnerability aggregation page catalogs security weaknesses associated with ImageMagick, a widely used software library for creating, editing, and composing bitmap images. The page collects data regarding common weaknesses such as buffer overflows, path traversal, and improper input validation that affect this specific product. The information covered spans from early discoveries in the library’s history through recent updates, providing a comprehensive timeline of security issues. Here, users can track vendor advisories issued by the ImageMagick development team to stay informed about patches and mitigation strategies. You can also gain a deeper understanding of specific weakness classes that impact image processing software, including how these flaws typically manifest in code. Additionally, the page allows you to look up a product's vulnerability history, enabling security professionals to assess risk trends and evaluate the impact of past incidents on the software’s stability. This resource is designed to support developers, security analysts, and system administrators in making informed decisions about software procurement, configuration, and maintenance. By consolidating these details into a single view, the page facilitates efficient monitoring of the security posture of ImageMagick installations. It serves as a reference for understanding the evolution of threats targeting this popular tool and helps identify patterns in reported vulnerabilities. Whether you are auditing your current environment or planning future deployments, this aggregation provides the necessary context to navigate the complex landscape of image processing security risks.

Vendor: ImageMagick

CVE IDTitleCVSSSeverityPublished
CVE-2026-61870 ImageMagick before 7.1.2-26 Memory Leak via VIFF Encoder CWE-401 2.9 Low2026-07-11
CVE-2026-61861 ImageMagick before 7.1.2-26 Use-After-Free in FormatMagickCaption CWE-416 3.7 Low2026-07-11
CVE-2026-61858 ImageMagick before 7.1.2-26 Policy Bypass via APNG encoder CWE-59 3.3 Low2026-07-11
CVE-2026-61857 ImageMagick before 7.1.2-26 Heap Use-After-Free via XMP CWE-252 3.7 Low2026-07-11
CVE-2026-61465 ImageMagick before 7.1.2-26 Memory Allocation Policy Bypass CWE-770 3.3 Low2026-07-11
CVE-2026-56372 ImageMagick - Heap Buffer Overflow Read via Unrecognized Magnify Method CWE-122 3.3 Low2026-07-11
CVE-2026-56373 ImageMagick - Use-After-Free Write in PDB Decoder CWE-416 3.7 Low2026-07-10
CVE-2026-56366 ImageMagick - Memory Leak in META Reader APP1JPEG Error Path CWE-401 3.3 Low2026-07-10
CVE-2026-56374 ImageMagick - Heap Buffer Overflow in FTXT Encoder via format Parameter CWE-125 3.3 Low2026-07-08
CVE-2026-56362 ImageMagick - Heap-buffer-overflow Read in GetPixelIndex via OpenPixelCache Metadata Desynchronization CWE-125 3.3 Low2026-07-08
CVE-2026-55597 ImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of arguments CWE-682 5.5 Medium2026-07-01
CVE-2026-55595 ImageMagick: Infinite Loop in connected-components when providing invalid arguments CWE-400 4.7 Medium2026-07-01
CVE-2026-55594 ImageMagick: Stack Overflow in MVG decoder due to missing depth check. CWE-400 5.3 Medium2026-07-01
CVE-2026-55577 ImageMagick: Heap Buffer Overflow in ImageMagick MVG decoder CWE-754 5.9 Medium2026-07-01
CVE-2026-55510 ImageMagick: Use-After-Free in crafted 8BIM when identifying an image CWE-416 5.5 Medium2026-07-01
CVE-2026-53467 ImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchanged CWE-908 5.3 Medium2026-07-01
CVE-2026-53466 ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow CWE-190 6.5 Medium2026-07-01
CVE-2026-55628 ImageMagick: Policy Bypass in concatenate operation due to missing checks CWE-73 5.5 Medium2026-07-01
CVE-2026-56377 ImageMagick - Policy Bypass via Incorrect Path Validation CWE-22 3.3 Low2026-06-30
CVE-2026-56369 ImageMagick - Information Disclosure via AES-CTR Nonce Reuse in PasskeyEncipherImage CWE-323 3.7 Low2026-06-30
CVE-2026-56364 ImageMagick - Memory Leak in LoadOpenCLDeviceBenchmark() via Malformed XML CWE-401 1.9 Low2026-06-30
CVE-2026-56365 ImageMagick - Memory Leak in PNG Encoder via MNG Image Writing CWE-401 3.7 Low2026-06-30
CVE-2026-56363 ImageMagick - Division by Zero in Binomial Kernel Processing CWE-190 3.3 Low2026-06-30
CVE-2026-56361 ImageMagick - Heap Buffer Overflow via Off-by-One in Morphology Processing CWE-125 3.3 Low2026-06-30
CVE-2026-56370 ImageMagick - Out-of-bounds Access in ConnectedComponentsImage via connected-components Artifact CWE-125 3.3 Low2026-06-24
CVE-2026-56368 ImageMagick - Memory Leak in Raw Pixel Data Coders CWE-401 3.7 Low2026-06-24
CVE-2026-56376 ImageMagick - Heap Use-After-Free in Meta Coder CWE-416 3.7 Low2026-06-23
CVE-2026-56379 ImageMagick - Command Injection via SVG Decoder CWE-116 8.1 High2026-06-23
CVE-2026-56371 ImageMagick - Memory Leak in TXT File Processing via Texture Attribute CWE-401 5.3 Medium2026-06-23
CVE-2026-56378 ImageMagick - Heap Out-of-Bounds Read in PCD Decoder CWE-125 3.7 Low2026-06-21

All 227 known CVE vulnerabilities affecting ImageMagick with full Chinese analysis, references, and POCs where available.