What is CVE-2026-66011?
This vulnerability exists in ImageMagick versions prior to 7.1.2-27, causing a memory leak in the magick command-line interface when invalid options are supplied. An attacker can exhaust system resources by repeatedly sending malformed arguments. Upgrading to at least version 7.1.2-27 is recommended to mitigate the risk.
Azərbaycanca: Bu zəiflik ImageMagick-in 7.1.2-27 versiyasından əvvəlki versiyalarında mövcuddur və magick komanda sətri interfeysində yanlış opsiyalar təqdim edildikdə memory leak yaradır. Təcavüzkar sistematik olaraq səhv arqumentlər göndərərək sistem resurslarını tükədə bilər. Təsirə məruz qalmamaq üçün ImageMagick-i ən azı 7.1.2-27 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which software is affected by CVE-2026-66011?
This vulnerability exists in ImageMagick versions prior to 7.1.2-27.
What measure should be taken to mitigate CVE-2026-66011?
Upgrading to at least version 7.1.2-27 is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.