CVE-2026-56369EPSS p13.8%
CVE-2026-56369CVE-2026-56369
imagemagick / imagemagick
Description
ImageMagick before 7.1.2-22 contains an information disclosure vulnerability in the PasskeyEncipherImage method due to AES-CTR nonce reuse. Attackers can exploit nonce reuse in the cipher implementation to recover plaintext information from encrypted images.
Scoring
| CVSS | 3.7 () |
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
| EPSS | 0.23% probability of exploitation · percentile 13.8% · 2026-08-14T12:00:27Z |
| Last modified | 2026-07-02 |