CVE-2026-56369

NameCVE-2026-56369
DescriptionImageMagick before 7.1.2-22 contains an information disclosure vulnerability in the PasskeyEncipherImage method due to AES-CTR nonce reuse. Attackers can exploit nonce reuse in the cipher implementation to recover plaintext information from encrypted images.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Notes

Bogus CVE assignment for imagemagick, was clarified in documentation
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qv2q-c278-pch5
Fixed by documentation upgrade https://github.com/ImageMagick/ImageMagick/issues/8837#event-27569522488

Search for package or bug name: Reporting problems