---
id: CVE-2026-61870
title: >-
  ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF
  encoder when memory allocation fails
summary: >-
  ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF
  encoder when memory allocation fails. Attackers can trigger allocation
  failures by processing specially crafted VIFF images to exhaust available
  memory and caus…
severity: low
cvss: 2.9
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-401
published: '2026-07-11'
updated: '2026-07-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-61870'
references:
  - url: >-
      https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-m596-67p7-69wh
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/imagemagick-before-26-memory-leak-via-viff-encoder
    label: disclosure@vulncheck.com
tags:
  - nvd
ingestedAt: '2026-07-12T00:16:39.381Z'
epss: 0.00317
epssPercentile: 0.21937
---

## Overview

ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF encoder when memory allocation fails. Attackers can trigger allocation failures by processing specially crafted VIFF images to exhaust available memory and cause denial of service.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
