CVE-2026-61871: ImageMagick before 7.1.2-26 Memory Leak in ICON decoder
Published Jul 15, 2026
·Updated
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the ICON decoder that occurs when a memory allocation fails. Processing a crafted ICON file that triggers an allocation failure leaks memory, which may lead to a denial of service.
Affected Software
2 affected components
ImageMagick ImageMagick<7.1.2-26
ImageMagick ImageMagick<6.9.13-51
Event History
Jul 15, 2026
CVE Published
via MITRE·11:25 AM
Data Sourced
via MITRE·11:25 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-61871?
The severity of CVE-2026-61871 is rated as low with a score of 3.7.
2
How do I fix CVE-2026-61871?
To fix CVE-2026-61871, update ImageMagick to version 7.1.2-26 or later.
3
What are the potential impacts of CVE-2026-61871?
The potential impact of CVE-2026-61871 is a denial of service due to a memory leak when processing a crafted ICON file.
4
Which versions of ImageMagick are affected by CVE-2026-61871?
CVE-2026-61871 affects ImageMagick versions before 7.1.2-26 and 6.9.13-51.
5
What type of vulnerability is CVE-2026-61871?
CVE-2026-61871 is a memory leak vulnerability found in the ICON decoder of ImageMagick.