Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-61864

CVE-2026-61864: ImageMagick Memory Leak DoS Vulnerability

CVE-2026-61864 is a memory leak denial-of-service flaw in ImageMagick affecting color transformation operations. The vulnerability causes memory to leak during failed log colorspace conversions. This article covers the technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2026-61864 Overview

CVE-2026-61864 is a memory leak vulnerability in ImageMagick affecting versions before 7.1.2-26 and 6.9.13-51. The flaw resides in the color transformation routine that converts images to the log colorspace. When the transformation operation fails, a small amount of allocated memory is not released back to the system. The issue is classified as a missing release of memory after effective lifetime [CWE-401]. Exploitation requires local access and repeated triggering of the failing operation to produce meaningful resource impact. The vulnerability does not enable code execution, privilege escalation, or information disclosure.

Critical Impact

Repeated failed log colorspace conversions can gradually exhaust process memory in long-running ImageMagick services, potentially degrading availability.

Affected Products

  • ImageMagick versions prior to 7.1.2-26
  • ImageMagick 6.x versions prior to 6.9.13-51
  • Applications and services embedding vulnerable ImageMagick libraries for image processing

Discovery Timeline

  • 2026-07-15 - CVE-2026-61864 published to NVD
  • 2026-07-15 - Last updated in NVD database

Technical Details for CVE-2026-61864

Vulnerability Analysis

The vulnerability is a memory leak triggered during color transformation to the log colorspace. ImageMagick allocates working memory to perform the conversion between colorspaces. When the conversion operation encounters a failure condition, the error handling path exits without freeing the previously allocated buffer. Each failed invocation leaks a small, bounded amount of heap memory. The leak is not exploitable for code execution or data exposure. Its practical impact is limited to gradual resource consumption in processes that repeatedly perform failing conversions, such as web-facing image processing pipelines.

Root Cause

The root cause is missing deallocation logic on the error path of the log colorspace transformation routine. This maps to [CWE-401], Missing Release of Memory After Effective Lifetime. The successful execution path releases memory correctly, but the failure branch omits the corresponding cleanup call, leaving the allocation orphaned for the lifetime of the process.

Attack Vector

Exploitation requires local access and the ability to submit crafted inputs that force the log colorspace conversion to fail. An attacker must invoke the conversion repeatedly to accumulate meaningful memory pressure. The vulnerability is not remotely reachable without an application layer that exposes ImageMagick conversion functionality to untrusted callers. No authentication is required at the ImageMagick layer itself. Detailed technical information is available in the GitHub Security Advisory and the VulnCheck Advisory on Memory Leak.

// No verified proof-of-concept code is available.
// Refer to the upstream security advisory for technical details.

Detection Methods for CVE-2026-61864

Indicators of Compromise

  • Gradual, unexplained increase in resident memory for processes invoking convert, magick, or applications linking libMagickCore
  • Repeated ImageMagick error log entries referencing colorspace transformation failures
  • Increased frequency of out-of-memory kills for image processing workers over time

Detection Strategies

  • Inventory installed ImageMagick versions across servers and container images and compare against fixed releases 7.1.2-26 and 6.9.13-51
  • Monitor process memory growth curves for services that call ImageMagick colorspace conversion routines
  • Enable ImageMagick policy logging to capture failed operations and correlate spikes with memory trends

Monitoring Recommendations

  • Alert on sustained resident set size growth in long-running image processing daemons
  • Track error rates for colorspace conversion operations at the application layer
  • Instrument image processing endpoints with per-request memory accounting to detect abusive input patterns

How to Mitigate CVE-2026-61864

Immediate Actions Required

  • Upgrade ImageMagick to version 7.1.2-26 or 6.9.13-51 or later on all affected systems
  • Rebuild container images and application bundles that statically or dynamically link vulnerable ImageMagick libraries
  • Restrict local access to systems running ImageMagick to trusted users only

Patch Information

The ImageMagick project addressed this issue in versions 7.1.2-26 and 6.9.13-51. Apply the vendor-supplied packages through your distribution's package manager, or install directly from the upstream release. Consult the GitHub Security Advisory for the fixed commit and full release notes.

Workarounds

  • Restart long-running ImageMagick worker processes on a scheduled basis to reclaim leaked memory until patching is complete
  • Configure ImageMagick policy.xml to constrain resource limits such as memory and map to bound worst-case consumption
  • Rate-limit or validate image inputs at the application layer to reduce the frequency of failing colorspace conversions
bash
# Example ImageMagick policy.xml resource limits
# <policymap>
#   <policy domain="resource" name="memory" value="256MiB"/>
#   <policy domain="resource" name="map" value="512MiB"/>
#   <policy domain="resource" name="time" value="60"/>
# </policymap>

# Verify installed version
magick -version | head -n 1

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.