Input Validation Issue in ImageSharp 2D Graphics Library
CVE-2026-106114

5.3MEDIUM

Key Information:

Vendor

Sixlabors

Vendor
CVE Published:
6 October 2026

What is CVE-2026-106114?

The ImageSharp 2D graphics library exhibits an input validation flaw that allows for improper allocation sizes during ICC CLUT parsing. This vulnerability arises when the library calculates memory allocations based on attacker-specified channel and grid dimensions without first validating that these dimensions are accurate. Specifically, the method IccDataReader.ReadClutF32 can be manipulated to request excessively large float arrays. This can lead to significant memory pressure and potential denial of service through resource exhaustion, particularly when the automatic conversion of images is used under DecoderOptions.ColorProfileHandling configured to 'Convert'. Versions prior to 4.1.2 possess this vulnerability, which has been remedied in the latest release.

Affected Version(s)

ImageSharp >= 1.0.0-beta0001, < 4.1.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.