Input Validation Issue in ImageSharp 2D Graphics Library
CVE-2026-106114
What is CVE-2026-106114?
The ImageSharp 2D graphics library exhibits an input validation flaw that allows for improper allocation sizes during ICC CLUT parsing. This vulnerability arises when the library calculates memory allocations based on attacker-specified channel and grid dimensions without first validating that these dimensions are accurate. Specifically, the method IccDataReader.ReadClutF32 can be manipulated to request excessively large float arrays. This can lead to significant memory pressure and potential denial of service through resource exhaustion, particularly when the automatic conversion of images is used under DecoderOptions.ColorProfileHandling configured to 'Convert'. Versions prior to 4.1.2 possess this vulnerability, which has been remedied in the latest release.
Affected Version(s)
ImageSharp >= 1.0.0-beta0001, < 4.1.2
