Out-of-Bounds Memory Write in ImageSharp for TIFF Images
CVE-2026-106115

7.5HIGH

Key Information:

Vendor

Sixlabors

Vendor
CVE Published:
6 October 2026

What is CVE-2026-106115?

The ImageSharp graphics library, versions 2.1.0 through 4.1.1, contains a vulnerability in its TIFF CCITT Group 4 encoder component. This flaw involves improper memory allocation when handling image data, specifically in the T6BitCompressor.CompressStrip function. Attackers can exploit this vulnerability through crafted input, leading to unchecked write operations in TiffCcittCompressor.WriteCode. Such exploitation could result in memory corruption, potentially crashing the application when processing TIFF images. The issue has been addressed in version 4.1.2.

Affected Version(s)

ImageSharp >= 2.1.0, < 4.1.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.