๐Ÿ” CVE Alert

CVE-2026-106116

MEDIUM 5.3

ImageSharp: BigTIFF IFD count can keep a decoder thread in a non-progressing loop

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, ExifReader.ReadValues64 trusts the 64-bit BigTIFF IFD entry count and iterates once per declared entry. When fewer than 20 bytes remain, ExifReader.ReadValue64 returns without advancing the stream or terminating the outer loop, so a small malformed BigTIFF can keep one decoder thread executing for an attacker-controlled duration. This report does not claim worker-pool exhaustion. This issue is fixed in version 4.1.2.

CWE CWE-835
Vendor sixlabors
Product imagesharp
Published Oct 6, 2026
Last Updated Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for sixlabors imagesharp

Be the first to know when new medium vulnerabilities affecting sixlabors imagesharp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low

Affected Versions

SixLabors / ImageSharp
>= 2.0.0, < 4.1.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-wmxv-xphr-5c9g github.com: https://github.com/SixLabors/ImageSharp/pull/3187 github.com: https://github.com/SixLabors/ImageSharp/commit/92b12d72550ebb6be5b1e22e559c361fd863a6ec github.com: https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2