Back to overview

CVE-2026-56364

LOW Exploitation: PoC
1.9
CVSS 3.1
Description
ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files to exhaust memory and cause denial of service.

Metadata

CVE ID
CVE-2026-56364
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-06-20 21:16 UTC
Published
2026-06-30 22:08 UTC
Last updated
2026-07-01 13:50 UTC
Primary CWE
CWE-401
Missing Release of Memory after Effective Lifetime
Vendor / Product
ImageMagick / ImageMagick
Sources
cve.org  ·  NVD

Severity & Metrics

1.9 LOW CVSS 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
ImageMagick ImageMagick 0 < 7.1.2-13, 7.1.2-13
Weakness (CWE)
CWESourceDescription
CWE-401 cna Missing Release of Memory after Effective Lifetime
CVSS scores (2)
ScoreSeverityVersionSourceVector
1.9 LOW 3.1 cna CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L
1.8 LOW 4.0 cna CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
References (3)
Back to overview