CVE-2026-61868: ImageMagick before 7.1.2-26 Memory Leak in YUV Decoder
Published Jul 15, 2026
·Updated
ImageMagick before 7.1.2-26 and 6.9.x before 6.9.13-51 contains a memory leak in the YUV decoder that occurs when opening of the blob fails. Repeated triggering can lead to resource exhaustion (denial of service).
Affected Software
2 affected components
ImageMagick ImageMagick<7.1.2-26
ImageMagick ImageMagick<6.9.13-51
Event History
Jul 15, 2026
CVE Published
via MITRE·11:25 AM
Data Sourced
via MITRE·11:25 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-61868?
The severity of CVE-2026-61868 is medium with a score of 6.3.
2
What software is affected by CVE-2026-61868?
CVE-2026-61868 affects ImageMagick versions before 7.1.2-26 and 6.9.x before 6.9.13-51.
3
How does CVE-2026-61868 impact system performance?
CVE-2026-61868 can lead to resource exhaustion, potentially causing a denial of service due to a memory leak in the YUV decoder.
4
How do I fix CVE-2026-61868?
To fix CVE-2026-61868, upgrade ImageMagick to version 7.1.2-26 or later, or 6.9.13-51 or later.
5
What causes the memory leak in CVE-2026-61868?
The memory leak in CVE-2026-61868 occurs when the opening of the blob fails in the YUV decoder.