๐Ÿ” CVE Alert

CVE-2026-106118

HIGH 7.5

ImageSharp: Tiled fax TIFF: tile buffer sized by TileWidth but fax decompressor writes scanlines of ImageWidth โ€” heap OOB write

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

ImageSharp is a 2D graphics library. From 3.0.0 until 4.1.1, tiled TIFF decoding allocates a destination buffer using TileWidth but TiffDecompressorsFactory.Create constructs T4, T6, and Modified Huffman decompressors using the full frame width. TiffDecoderCore.DecodeTilesChunky can therefore direct frame-width fax scanlines into a tile-width buffer when TileWidth is smaller than ImageWidth. The mismatch causes attacker-controlled out-of-bounds writes, heap corruption, and process termination even with legal per-row run codes. This tiled-path vulnerability is distinct from oversized CCITT runs in strip decoding. This issue is fixed in version 4.1.1.

CWE CWE-787
Vendor sixlabors
Product imagesharp
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for sixlabors imagesharp

Be the first to know when new high vulnerabilities affecting sixlabors imagesharp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

SixLabors / ImageSharp
>= 3.0.0, < 4.1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-v76p-62qx-wwq2 github.com: https://github.com/SixLabors/ImageSharp/pull/3176 github.com: https://github.com/SixLabors/ImageSharp/commit/9ee7d1dd5b62d8c9f16cc755e76828386bc2191f github.com: https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.1