The PasskeyEncipherImage method is vulnerable to information disclosure via AES-CTR nonce reuse. ImageMagick has update the documentation on its website to make it more clear that this is happening: https://imagemagick.org/cipher/
{
"github_reviewed_at": "2026-05-21T21:49:09Z",
"nvd_published_at": null,
"github_reviewed": true,
"severity": "LOW",
"cwe_ids": [
"CWE-323",
"CWE-330"
]
}