Memory Corruption Issue in ImageSharp Graphics Library Affecting TIFF Compression
CVE-2026-106110

7.5HIGH

Key Information:

Vendor

Sixlabors

Vendor
CVE Published:
6 October 2026

What is CVE-2026-106110?

A vulnerability in the ImageSharp library allows attackers to exploit memory corruption issues related to the TIFF CCITT Group 3 encoder. The flawed handling of 1-bit narrow image buffers can lead to unchecked writes beyond allocated memory during encoding and decoding processes. This may result in process memory corruption and can cause instability in applications using affected versions of ImageSharp. Users are advised to update to version 4.1.2 or later for protection against this vulnerability.

Affected Version(s)

ImageSharp >= 2.0.0, < 4.1.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.