ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, a crafted image could result in an out of bounds heap write when writing a yaml or json output, resulting in a crash. This issue has been fixed in version 7.1.2-19.
{
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40169.json",
"cwe_ids": [
"CWE-122",
"CWE-787"
]
}{
"source": "REFERENCES"
}
{
"cpe": "cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "7.1.2-19"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"2026-08-07T20:13:13Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40169.json"
[
{
"signature_type": "Function",
"target": {
"file": "coders/json.c",
"function": "EncodeImageAttributes"
},
"deprecated": false,
"digest": {
"length": 24082.0,
"function_hash": "79855461008403424504161711453767019504"
},
"signature_version": "v1",
"source": "https://github.com/imagemagick/imagemagick/commit/f86452a8aea37bf2b4bd36127f836dcc5f138b38",
"id": "CVE-2026-40169-3907a44e"
},
{
"signature_type": "Line",
"target": {
"file": "coders/json.c"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"137818908466362065724160206685836090050",
"44847121230848472340199582299187548347",
"56465510995814983157872720154225934707",
"20354588599952792342081989774099586817",
"101294160819922131902498117744241557368",
"269594860865838498134212413582478615009",
"233801776097519125425901318044251397663",
"99904321502344789658567016270517749025",
"226854737856900752451879766465318878203",
"130940929663841558054455410524695788530",
"236622011063491213556594094764071610893",
"301881098667017633208662867896983662637",
"100003100529655588055906849461187689037",
"299558084673832297133548391051928722505",
"21317831344499548848538759370416750116",
"4166519676162139488092195133992354303"
]
},
"signature_version": "v1",
"source": "https://github.com/imagemagick/imagemagick/commit/f86452a8aea37bf2b4bd36127f836dcc5f138b38",
"id": "CVE-2026-40169-8ca750da"
},
{
"signature_type": "Line",
"target": {
"file": "coders/yaml.c"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"80442661561830723625889112535732840761",
"101503015264853044161557351536582923995",
"59537404271470227683282955022159073825",
"20354588599952792342081989774099586817",
"101294160819922131902498117744241557368",
"269594860865838498134212413582478615009",
"233801776097519125425901318044251397663",
"99904321502344789658567016270517749025",
"176093872386795684405974045961558032269",
"265126284602319794737998367815845733473",
"205327739484433783244015711862646396543"
]
},
"signature_version": "v1",
"source": "https://github.com/imagemagick/imagemagick/commit/f86452a8aea37bf2b4bd36127f836dcc5f138b38",
"id": "CVE-2026-40169-bca15113"
},
{
"signature_type": "Function",
"target": {
"file": "coders/yaml.c",
"function": "EncodeImageAttributes"
},
"deprecated": false,
"digest": {
"length": 23204.0,
"function_hash": "83011474777441121961158149898916005057"
},
"signature_version": "v1",
"source": "https://github.com/imagemagick/imagemagick/commit/f86452a8aea37bf2b4bd36127f836dcc5f138b38",
"id": "CVE-2026-40169-da8ffcad"
}
]