Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-61863

CVE-2026-61863: ImageMagick TIFF Encoder DoS Vulnerability

CVE-2026-61863 is a denial of service vulnerability in ImageMagick's TIFF encoder caused by a memory leak when temporary files cannot be created. This article covers the technical details, affected versions, and mitigation.

Published:

CVE-2026-61863 Overview

CVE-2026-61863 is a memory leak vulnerability in ImageMagick affecting versions before 7.1.2-26 and 6.x versions before 6.9.13-51. The flaw resides in the TIFF encoder and triggers when the encoder fails to create a temporary file. Each failed encoding operation leaks a small amount of process memory, mapped to [CWE-401] Missing Release of Memory After Effective Lifetime. The issue requires local access and high attack complexity to exploit, limiting its practical impact to availability degradation over time.

Critical Impact

Repeated triggering of the failed TIFF encoding path causes incremental memory exhaustion in long-running ImageMagick processes.

Affected Products

  • ImageMagick versions prior to 7.1.2-26
  • ImageMagick 6.x versions prior to 6.9.13-51
  • Applications and services embedding vulnerable ImageMagick libraries for TIFF encoding

Discovery Timeline

  • 2026-07-15 - CVE-2026-61863 published to NVD
  • 2026-07-16 - Last updated in NVD database

Technical Details for CVE-2026-61863

Vulnerability Analysis

The vulnerability is a memory leak in the ImageMagick TIFF encoder. When the encoder attempts to create a temporary file and that operation fails, the error handling path does not release memory previously allocated for the encoding operation. Each failed invocation leaks a small buffer.

The defect falls under [CWE-401], Missing Release of Memory After Effective Lifetime. Impact is limited to availability. There is no confidentiality or integrity impact, and no code execution primitive.

The EPSS score is 0.187%, reflecting a low likelihood of exploitation in the near term. No public proof-of-concept exists and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

Root Cause

The TIFF encoder allocates working memory before attempting to create a temporary file used during encoding. When temporary file creation fails, the encoder returns an error without freeing the previously allocated buffer. This missing cleanup on the error path is the source of the leak.

Attack Vector

Exploitation requires local access and repeated invocation of the TIFF encoder under conditions where temporary file creation fails. An attacker with local access could induce failure conditions by exhausting temporary storage, restricting filesystem permissions, or setting resource limits. Sustained triggering degrades service availability by consuming process memory.

No verified exploit code is available. The vulnerability is described in the GitHub Security Advisory and the VulnCheck Security Advisory.

Detection Methods for CVE-2026-61863

Indicators of Compromise

  • Gradual increase in resident memory for processes linking ImageMagick that perform TIFF encoding
  • Failed temporary file creation events in /tmp or the configured MAGICK_TMPDIR correlated with TIFF write operations
  • Repeated ImageMagick error log entries referencing TIFF encoding failures

Detection Strategies

  • Inventory installed ImageMagick versions across servers and containers, flagging any release below 7.1.2-26 or 6.9.13-51
  • Monitor long-running image processing workers for unbounded memory growth over multi-day windows
  • Instrument application logs to capture ImageMagick exceptions returned from TIFF encode operations

Monitoring Recommendations

  • Establish baselines for memory consumption of image processing services and alert on sustained upward drift
  • Track filesystem free space and inode availability on temporary file directories used by ImageMagick
  • Correlate spikes in TIFF conversion request volume with process restart frequency

How to Mitigate CVE-2026-61863

Immediate Actions Required

  • Upgrade ImageMagick to version 7.1.2-26 or later, or apply the 6.9.13-51 update for the 6.x branch
  • Rebuild and redeploy any applications or container images that bundle ImageMagick libraries
  • Restart long-running services using ImageMagick to reclaim any memory already leaked

Patch Information

The upstream fix is published in the GitHub Security Advisory GHSA-6vxp-gfwf-hcr9. Distributions repackaging ImageMagick should carry the fix in updates aligned with versions 7.1.2-26 and 6.9.13-51. Verify installed package versions against vendor advisories before considering systems remediated.

Workarounds

  • Ensure the temporary directory used by ImageMagick has adequate free space and correct write permissions to prevent the failing code path from executing
  • Configure process supervisors to recycle image processing workers on a schedule or memory threshold as a compensating control
  • Restrict local access to systems performing TIFF encoding to reduce the attack surface until patches are applied
bash
# Verify installed ImageMagick version
magick -version | head -n 1

# Debian/Ubuntu upgrade example
sudo apt-get update && sudo apt-get install --only-upgrade imagemagick

# RHEL/Fedora upgrade example
sudo dnf upgrade ImageMagick

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.