---
id: CVE-2026-66011
title: >-
  ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick
  command-line interface when invalid options are provided
summary: >-
  ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick
  command-line interface when invalid options are provided. Attackers can
  trigger memory exhaustion by repeatedly supplying malformed command-line
  arguments to …
severity: low
cvss: 3.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'
cwe:
  - CWE-401
published: '2026-07-25'
updated: '2026-07-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-66011'
references:
  - url: >-
      https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-cvhv-g4rq-3hmw
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/imagemagick-before-27-memory-leak-via-invalid-cli-options
    label: disclosure@vulncheck.com
tags:
  - nvd
ingestedAt: '2026-07-26T11:12:02.940Z'
epss: 0.00134
epssPercentile: 0.02361
---

## Overview

ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options are provided. Attackers can trigger memory exhaustion by repeatedly supplying malformed command-line arguments to consume system resources.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
