Security Advisory

CVE-2026-56369

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-30 22:08:38
Last updated 2026-07-01 15:07:57
Assigner VulnCheck
CVSS score 6.3
State PUBLISHED

Description

ImageMagick before 7.1.2-22 contains an information disclosure vulnerability in the PasskeyEncipherImage method due to AES-CTR nonce reuse. Attackers can exploit nonce reuse in the cipher implementation to recover plaintext information from encrypted images.