LOW 3.7 NuGet
ImageMagick: Information Disclosure in PasskeyEncipherImage via AES-CTR nonce reuse
GHSA-qv2q-c278-pch5 · CVE-2026-56369
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
The PasskeyEncipherImage method is vulnerable to information disclosure via AES-CTR nonce reuse. ImageMagick has update the documentation on its website to make it more clear that this is happening: https://imagemagick.org/cipher/
Ready to move
Start Securing
Free, no credit card | First findings in minutes