CVE-2026-61866: ImageMagick before 7.1.2-26 Memory Leak in JNG encoder
Published Jul 15, 2026
·Updated
ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attackers can trigger the memory leak by providing malformed JNG files that fail blob operations, causing resource exhaustion.
Affected Software
2 affected components
ImageMagick ImageMagick<7.1.2-26
ImageMagick ImageMagick<7.1.2-26
Event History
Jul 15, 2026
CVE Published
via MITRE·11:25 AM
Data Sourced
via MITRE·11:25 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:18 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-61866?
CVE-2026-61866 has a low severity rating of 2.1.
2
How do I fix CVE-2026-61866?
To fix CVE-2026-61866, upgrade to ImageMagick version 7.1.2-26 or later.
3
What causes CVE-2026-61866?
CVE-2026-61866 is caused by a memory leak in the JNG encoder when it fails to open a malformed JNG file.
4
What are the potential impacts of CVE-2026-61866?
The potential impact of CVE-2026-61866 is resource exhaustion due to memory leaks.
5
Is CVE-2026-61866 exploitable by attackers?
Yes, attackers can exploit CVE-2026-61866 by providing malformed JNG files.