| Name | CVE-2026-56369 |
| Description | ImageMagick before 7.1.2-22 contains an information disclosure vulnerability in the PasskeyEncipherImage method due to AES-CTR nonce reuse. Attackers can exploit nonce reuse in the cipher implementation to recover plaintext information from encrypted images. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Bogus CVE assignment for imagemagick, was clarified in documentation
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qv2q-c278-pch5
Fixed by documentation upgrade https://github.com/ImageMagick/ImageMagick/issues/8837#event-27569522488