Denial of Service in ImageSharp 2D Graphics Library
CVE-2026-106116
5.3MEDIUM
What is CVE-2026-106116?
The ImageSharp library, utilized for 2D graphics processing, contains a vulnerability within the ExifReader component. Specifically, the ReadValues64 method improperly handles the 64-bit BigTIFF IFD entry count. When fewer than 20 bytes remain in the stream, it fails to advance the read position or break the processing loop, which can result in excessive CPU resource usage as an attacker may leverage malformed BigTIFF files to keep a decoding thread active indefinitely. This design flaw can impact application performance but does not lead to worker pool exhaustion. The issue has been resolved in version 4.1.2.
Affected Version(s)
ImageSharp >= 2.0.0, < 4.1.2
