CVE-2026-61857
LOW3.7CVSS v3
—CVSS v2
0.27%
EPSS (exploit probability)
CWE-252CWE
Description
ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null check when parsing XMP profiles. Attackers can craft malicious image files with specially crafted XMP data to trigger the vulnerability and cause application crashes.
CVSS v3 vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected routers (0)
No routers currently mapped to this CVE in our database.