ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, a crafted image could result in an out of bounds heap write when writing a yaml or json output, resulting in a crash. This issue has been fixed in version 7.1.2-19.
{
"cwe_ids": [
"CWE-122",
"CWE-787"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40169.json",
"cna_assigner": "GitHub_M"
}{
"source": "REFERENCES"
}{
"cpe": "cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "7.1.2-19"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}[
{
"source": "https://github.com/imagemagick/imagemagick/commit/f86452a8aea37bf2b4bd36127f836dcc5f138b38",
"signature_version": "v1",
"signature_type": "Function",
"digest": {
"function_hash": "79855461008403424504161711453767019504",
"length": 24082.0
},
"deprecated": false,
"id": "CVE-2026-40169-3907a44e",
"target": {
"function": "EncodeImageAttributes",
"file": "coders/json.c"
}
},
{
"digest": {
"line_hashes": [
"137818908466362065724160206685836090050",
"44847121230848472340199582299187548347",
"56465510995814983157872720154225934707",
"20354588599952792342081989774099586817",
"101294160819922131902498117744241557368",
"269594860865838498134212413582478615009",
"233801776097519125425901318044251397663",
"99904321502344789658567016270517749025",
"226854737856900752451879766465318878203",
"130940929663841558054455410524695788530",
"236622011063491213556594094764071610893",
"301881098667017633208662867896983662637",
"100003100529655588055906849461187689037",
"299558084673832297133548391051928722505",
"21317831344499548848538759370416750116",
"4166519676162139488092195133992354303"
],
"threshold": 0.9
},
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/imagemagick/imagemagick/commit/f86452a8aea37bf2b4bd36127f836dcc5f138b38",
"deprecated": false,
"id": "CVE-2026-40169-8ca750da",
"target": {
"file": "coders/json.c"
}
},
{
"source": "https://github.com/imagemagick/imagemagick/commit/f86452a8aea37bf2b4bd36127f836dcc5f138b38",
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"line_hashes": [
"80442661561830723625889112535732840761",
"101503015264853044161557351536582923995",
"59537404271470227683282955022159073825",
"20354588599952792342081989774099586817",
"101294160819922131902498117744241557368",
"269594860865838498134212413582478615009",
"233801776097519125425901318044251397663",
"99904321502344789658567016270517749025",
"176093872386795684405974045961558032269",
"265126284602319794737998367815845733473",
"205327739484433783244015711862646396543"
],
"threshold": 0.9
},
"deprecated": false,
"id": "CVE-2026-40169-bca15113",
"target": {
"file": "coders/yaml.c"
}
},
{
"source": "https://github.com/imagemagick/imagemagick/commit/f86452a8aea37bf2b4bd36127f836dcc5f138b38",
"signature_version": "v1",
"signature_type": "Function",
"digest": {
"function_hash": "83011474777441121961158149898916005057",
"length": 23204.0
},
"deprecated": false,
"id": "CVE-2026-40169-da8ffcad",
"target": {
"function": "EncodeImageAttributes",
"file": "coders/yaml.c"
}
}
]
"2026-07-15T15:56:18Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40169.json"