Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4497-1 | imagemagick security update |
Debian DSA |
DSA-6158-1 | imagemagick security update |
Debian DSA |
DSA-6159-1 | imagemagick security update |
Github GHSA |
GHSA-96pc-27rx-pr36 | ImageMagick has Possible Heap Information Disclosure in PSD ZIP Decompression |
Thu, 26 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 24 Feb 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:* |
Tue, 24 Feb 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Imagemagick
Imagemagick imagemagick |
|
| Vendors & Products |
Imagemagick
Imagemagick imagemagick |
Tue, 24 Feb 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap information disclosure vulnerability exists in ImageMagick's PSD (Adobe Photoshop) format handler. When processing a maliciously crafted PSD file containing ZIP-compressed layer data that decompresses to less than the expected size, uninitialized heap memory is leaked into the output image. Versions 7.1.2-15 and 6.9.13-40 contain a patch. | |
| Title | ImageMagick has Possible Heap Information Disclosure in PSD ZIP Decompression | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-26T14:40:07.564Z
Reserved: 2026-01-23T00:38:20.548Z
Link: CVE-2026-24481
Updated: 2026-02-26T14:39:54.664Z
Status : Analyzed
Published: 2026-02-24T01:16:12.423
Modified: 2026-02-24T17:42:17.567
Link: CVE-2026-24481
No data.
OpenCVE Enrichment
Updated: 2026-04-17T16:15:22Z
Debian DLA
Debian DSA
Github GHSA