Out-of-Bounds Memory Write in ImageSharp for TIFF Images
CVE-2026-106115
7.5HIGH
What is CVE-2026-106115?
The ImageSharp graphics library, versions 2.1.0 through 4.1.1, contains a vulnerability in its TIFF CCITT Group 4 encoder component. This flaw involves improper memory allocation when handling image data, specifically in the T6BitCompressor.CompressStrip function. Attackers can exploit this vulnerability through crafted input, leading to unchecked write operations in TiffCcittCompressor.WriteCode. Such exploitation could result in memory corruption, potentially crashing the application when processing TIFF images. The issue has been addressed in version 4.1.2.
Affected Version(s)
ImageSharp >= 2.1.0, < 4.1.2
