{"id":"CVE-2026-56371","title":"ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture attributes: the texture object allocated via ReadImage is not released when GetTypeMetrics fails, leaking memory each…","summary":"ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture attributes: the texture object allocated via ReadImage is not released when GetTypeMetrics fails, leaking memory each…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":["CWE-401"],"vendor":"imagemagick","product":"imagemagick","affected":["imagemagick < 6.9.13-40","imagemagick >= 7.0.0-0, < 7.1.2-15"],"patched":["imagemagick 7.1.2-15"],"published":"2026-06-23","updated":"2026-07-02","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-56371","references":[{"url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3q5f-gmjc-38r8","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/imagemagick-memory-leak-in-txt-file-processing-via-texture-attribute","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"epss":0.00257,"epssPercentile":0.17668,"ingestedAt":"2026-07-03T13:02:27.819Z","slug":"CVE-2026-56371","body":"## Overview\n\nImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture attributes: the texture object allocated via ReadImage is not released when GetTypeMetrics fails, leaking memory each time a crafted TXT file with a texture attribute is processed.\n\n## Affected\n\n- `imagemagick < 6.9.13-40`\n- `imagemagick >= 7.0.0-0, < 7.1.2-15`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `imagemagick 7.1.2-15`","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}