Sceawere

Vulnerability Detail

CVE-2026-106110UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

ImageSharp TIFF Buffer Overflow

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
7h ago
Vendor
SixLabors
Product
ImageSharp
Attack Type
CWE-787: Out-of-bounds Write
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Group 3 encoder allocates an undersized compressed-data buffer for narrow 1-bit images. TiffCcittCompressor.Initialize does not reserve enough space for the row data and T4 end-of-line codes, and T4BitCompressor.CompressStrip reaches unchecked writes when TiffCompression.CcittGroup3Fax is selected directly or inherited from decoded TIFF metadata. An attacker-controlled encode or decode-and-re-encode flow can write beyond the logical output span, corrupt process memory, and terminate the process. This issue is fixed in version 4.1.2.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-06T18:16:52.490Z",
  "pubdate": "2026-10-06T18:16:52.490Z",
  "executiveSummary": "The ImageSharp graphics library contains a heap-based buffer overflow vulnerability within its TIFF CCITT Group 3 encoder component. This flaw, affecting versions 2.0.0 through 4.1.2, stems from an improper calculation of memory requirements for narrow 1-bit images.\nThe vulnerability allows an attacker to trigger an out-of-bounds write beyond the allocated logical output span during the image encoding or transcoding process. By providing a specially crafted image, an attacker can corrupt process memory, leading to unpredictable system behavior or a crash (denial of service).\nExploitation is feasible if the library processes attacker-controlled input, either via direct encoding or through a decode-and-re-encode workflow where the compression type is set to TiffCompression.CcittGroup3Fax. As this is a memory corruption issue, it poses significant security risks in environments where image processing is performed on untrusted data. Users are strongly advised to update to version 4.1.2 or later to remediate the flaw.",
  "technicalDetails": "The vulnerability resides in the TiffCcittCompressor.Initialize function within the ImageSharp library. The root cause is an undersized memory allocation for the compressed-data buffer intended to hold 1-bit row data and the associated T4 end-of-line (EOL) codes.\nSpecifically, the TiffCcittCompressor fails to account for the necessary buffer padding required for narrow image widths when processing CCITT Group 3 fax compression. When the T4BitCompressor.CompressStrip method executes, it performs write operations based on the assumption that the buffer is sufficiently sized for the encoded bitstream. Because the initial allocation is insufficient, the compressor writes past the boundary of the destination buffer into adjacent heap memory.\nThe attack vector involves a two-stage process. First, an attacker must supply a malicious image file to the library. If the image is subsequently processed using TiffCompression.CcittGroup3Fax, the library triggers the vulnerable code path. This can occur either by explicitly selecting the CCITT Group 3 compression mode or by having the compression settings inherited from the metadata of a previously decoded TIFF file.\nDuring the compression of a strip, the unchecked writes in T4BitCompressor.CompressStrip facilitate the corruption of heap metadata or adjacent application data. This memory corruption can lead to immediate process termination, effectively resulting in a denial-of-service condition. Furthermore, if the overflow can be controlled, it may potentially allow for arbitrary code execution or the bypass of security controls, depending on the heap layout and the specific runtime environment.\nThe vulnerability persists in all versions from 2.0.0 up to and including 4.1.1. No authentication or elevated privileges are required to initiate the vulnerability, provided that the application utilizes the ImageSharp library to handle TIFF files supplied by an untrusted source. The exploit is typically triggered via the standard image manipulation API calls within the library's processing pipeline."
}
CVE-2026-106110: ImageSharp TIFF Buffer Overflow (HIGH Severity, CVSS: 7.5) | Sceawere