Description
ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the FTXT encoder due to missing boundary checks when parsing ftxt:format. Remote attackers can trigger an out of bounds read by crafting malicious FTXT image files to cause denial of service or information disclosure.
Published: 2026-07-08
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

ImageMagick libraries vulnerable to a heap buffer overflow in the FTXT encoder due to missing boundary checks when parsing the ftxt:format parameter. A remote attacker can supply a crafted FTXT image file that triggers an out‑of‑bounds read, permitting either a denial of service or a partial information disclosure by exposing data located beyond the intended buffer. This flaw restricts the confidentiality and availability of a system that processes untrusted FTXT images and can be exercised over the network.

Affected Systems

All installations of ImageMagick earlier than version 7.1.2‑19 are affected, including the open source ImageMagick distribution identified by the vendor ImageMagick and product ImageMagick. The vulnerability exists regardless of the host operating system and applies to all builds that support the FTXT format encoder.

Risk and Exploitability

The CVSS score of 4.8 indicates a moderate severity, and the EPSS score is < 1%, indicating a very low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Attackers can exploit the vulnerability remotely by sending malicious FTXT files to an application that processes images through ImageMagick, making the risk primarily a denial‑of‑service or information disclosure threat to systems that accept untrusted images.

Generated by OpenCVE AI on July 26, 2026 at 17:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ImageMagick to version 7.1.2‑19 or later to apply the patch, disable or restrict the use of the FTXT image format, or enforce strict validation of the ftxt:format parameter to prevent out‑of‑bounds reads.
  • Implement monitoring or rate limiting on image processing to detect and mitigate potential denial‑of‑service attacks stemming from malformed FTXT files.
  • Check for new ImageMagick releases or advisories to stay updated on security patches.

Generated by OpenCVE AI on July 26, 2026 at 17:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Low


Wed, 08 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Description ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the FTXT encoder due to missing boundary checks when parsing ftxt:format. Remote attackers can trigger an out of bounds read by crafting malicious FTXT image files to cause denial of service or information disclosure.
Title ImageMagick - Heap Buffer Overflow in FTXT Encoder via format Parameter
First Time appeared Imagemagick
Imagemagick imagemagick
Weaknesses CWE-125
CPEs cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
Vendors & Products Imagemagick
Imagemagick imagemagick
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Imagemagick Imagemagick
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-08T15:46:51.394Z

Reserved: 2026-06-21T02:05:21.920Z

Link: CVE-2026-56374

cve-icon Vulnrichment

Updated: 2026-07-08T15:46:48.490Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Low

Publid Date: 2026-07-08T13:49:04Z

Links: CVE-2026-56374 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T18:00:05Z

Weaknesses