ImageSharp 2D Graphics Library Vulnerability Affecting Floating-Point TIFF Decoding
CVE-2026-106113

7.5HIGH

Key Information:

Vendor

Sixlabors

Vendor
CVE Published:
6 October 2026

What is CVE-2026-106113?

ImageSharp, a popular 2D graphics library, is susceptible to a vulnerability where decoding an attacker-controlled 32-bit floating-point TIFF can lead to non-finite or out-of-range luminance values in the ColorNumerics.GetBT709Luminance method. This error can result in unchecked histogram offset usage in the GrayscaleLevelsRowOperation.Invoke function, potentially causing an unsafe out-of-bounds access and resulting in process termination. This vulnerability affects versions from 2.0.0 to 4.1.1 and is resolved in version 4.1.2. Adaptive Histogram Equalization and AutoLevel features remain unaffected.

Affected Version(s)

ImageSharp >= 2.0.0, < 4.1.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.