ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-15, a memory leak in the ASHLAR image writer allows an attacker to exhaust process memory by providing a crafted image that results in small objects that are allocated but never freed. Version 7.1.2-15 contains a patch.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25637.json",
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-401"
]
}[
{
"id": "CVE-2026-25637-4f67f6e3",
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/imagemagick/imagemagick/commit/30ce0e8efbd72fd6b50ed3a10ae22f57c8901137",
"target": {
"function": "ASHLARImage",
"file": "coders/ashlar.c"
},
"digest": {
"length": 4986.0,
"function_hash": "197829779831936446585692757351336901776"
},
"signature_type": "Function"
},
{
"id": "CVE-2026-25637-f61c079a",
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/imagemagick/imagemagick/commit/30ce0e8efbd72fd6b50ed3a10ae22f57c8901137",
"target": {
"file": "coders/ashlar.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"68684419820363235162443921224781845528",
"142122473368606438402161395866429963687",
"247334712507425837238920063784528962791",
"251857013250987471861868039019942996576",
"203607486525013578609151241005575810859",
"180369377576925790430250461038904933852",
"180465836591910686251537318021911048198",
"307797523096124783215953513896932298083",
"163416129225790202101553728221141394659",
"327274440290168931103842030775155621384",
"181672060570690022310984220251373039423",
"130325334314780139583311272769459631318",
"90709304575448347531528549611242769029"
]
},
"signature_type": "Line"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-25637.json"