Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.
JLSEC-2026-1063 Medium 6.3

ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null...

JLSEC Published
Modified
Severity
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Affected Packages
ImageMagick_jll < 7.1.2028+0

ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null check when parsing XMP profiles. Attackers can craft malicious image files with specially crafted XMP data to trigger the vulnerability and cause application crashes.

References