CVE-2026-66011: ImageMagick before 7.1.2-27 Memory Leak via Invalid CLI Options
Published Jul 25, 2026
·Updated
ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options are provided. Attackers can trigger memory exhaustion by repeatedly supplying malformed command-line arguments to consume system resources.
Affected Software
1 affected component
ImageMagick ImageMagick<7.1.2-27
Event History
Jul 25, 2026
CVE Published
via MITRE·10:45 AM
Data Sourced
via MITRE·10:45 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-66011?
The severity of CVE-2026-66011 is rated as low with a score of 3.3.
2
What does CVE-2026-66011 involve?
CVE-2026-66011 involves a memory leak vulnerability in ImageMagick's command-line interface caused by invalid options.
3
How do I fix CVE-2026-66011?
To fix CVE-2026-66011, update ImageMagick to version 7.1.2-27 or later.
4
What can attackers do with CVE-2026-66011?
Attackers can exploit CVE-2026-66011 to trigger memory exhaustion by supplying malformed command-line arguments.
5
Which versions of ImageMagick are affected by CVE-2026-66011?
CVE-2026-66011 affects versions of ImageMagick prior to 7.1.2-27.