Description
ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printed (read past the profile boundary). This behavior occurs when debug output is enabled.
Published: 2026-07-15
Score: 2.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

ImageMagick versions before 7.1.2‑26 and before 6.9.13‑51 allow an attacker to read a single byte beyond the end of a profile buffer when the identify command is run with debug output enabled and the profile value is not printable. The vulnerability is an out‑of‑bounds read (CWE‑125) that can disclose one byte of data.

Affected Systems

The affected product is ImageMagick from the ImageMagick vendor. All releases prior to 7.1.2‑26 and prior to 6.9.13‑51 are vulnerable.

Risk and Exploitability

The CVSS score of 2.1 indicates low overall impact, and the EPSS score of less than 1 % suggests a very low exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the identify command to be executed with debug output enabled. No privilege escalation or remote code execution is achieved by this flaw.

Generated by OpenCVE AI on August 1, 2026 at 08:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ImageMagick to version 7.1.2‑26 or later (or 6.9.13‑51 or later) to remove the out‑of‑bounds read.
  • Configure the system to prevent the identify command from running with the debug flag; disable or restrict debug output for ImageMagick tools.
  • Ensure that the identify command is only invoked by trusted users or restricted services, and remove any public exposure to untrusted inputs (e.g., block web interfaces that allow arbitrary identify calls).

Generated by OpenCVE AI on August 1, 2026 at 08:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4696-1 imagemagick security update
History

Thu, 16 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Low


Wed, 15 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Description ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printed (read past the profile boundary). This behavior occurs when debug output is enabled.
Title ImageMagick before 7.1.2-26 Information Disclosure via identify
First Time appeared Imagemagick
Imagemagick imagemagick
Weaknesses CWE-125
CPEs cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
Vendors & Products Imagemagick
Imagemagick imagemagick
References
Metrics cvssV3_1

{'score': 2.9, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Imagemagick Imagemagick
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-15T13:51:41.638Z

Reserved: 2026-07-10T21:53:55.769Z

Link: CVE-2026-61862

cve-icon Vulnrichment

Updated: 2026-07-15T13:51:35.149Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Low

Publid Date: 2026-07-15T11:25:49Z

Links: CVE-2026-61862 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:00:04Z

Weaknesses