SEPTEMBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-61868

LOW · CVSS 3.7 EPSS 0.22% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

ImageMagick versions prior to 7.1.2-26 and 6.9.x before 6.9.13-51 are susceptible to a memory leak in the YUV decoder, which occurs when the opening of a blob fails. This vulnerability can be exploited to cause resource exhaustion, potentially leading to a denial of service. Organizations using affected versions should prioritize patching to mitigate the risk of service disruption.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-61868
Severity
LOW
CVSS
3.7
EPSS
0.22%

Original NVD Description

ImageMagick before 7.1.2-26 and 6.9.x before 6.9.13-51 contains a memory leak in the YUV decoder that occurs when opening of the blob fails. Repeated triggering can lead to resource exhaustion (denial of service).