CVE-2026-61867: ImageMagick before 7.1.2-26 Memory Leak in TIFF Encoder
Published Jul 15, 2026
·Updated
ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the TIFF encoder when memory allocation fails. Attackers can trigger allocation failures during TIFF image processing to cause memory exhaustion and denial of service.
Affected Software
1 affected component
ImageMagick ImageMagick<7.1.2-26
Event History
Jul 15, 2026
CVE Published
via MITRE·11:25 AM
Data Sourced
via MITRE·11:25 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-61867?
CVE-2026-61867 has a severity rating of low, specifically a score of 2.1.
2
How do I fix CVE-2026-61867?
To fix CVE-2026-61867, update ImageMagick to version 7.1.2-26 or later.
3
What impact does CVE-2026-61867 have on system security?
CVE-2026-61867 can lead to memory exhaustion, resulting in a denial of service.
4
Who is affected by CVE-2026-61867?
Any user or organization using ImageMagick versions prior to 7.1.2-26 is affected by CVE-2026-61867.
5
What is the nature of the vulnerability in CVE-2026-61867?
CVE-2026-61867 is a memory leak vulnerability occurring in the TIFF encoder during memory allocation failures.