Sceawere
Vulnerability Detail
CVE-2026-106114UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
ImageSharp ICC Parsing Memory Exhaustion
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 7h ago
- Vendor
- SixLabors
- Product
- ImageSharp
- Attack Type
- CWE-789: Memory Allocation with Excessive Size Value
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
ImageSharp is a 2D graphics library. From 1.0.0-beta0001 until 4.1.2, ICC CLUT parsing calculates allocation sizes from attacker-declared channel and grid dimensions before confirming that the profile contains the declared values. IccDataReader.ReadClutF32 can request a large float array, and earlier public IccProfile.Entries parsing paths can allocate a large jagged representation, from a short truncated profile. In version 4, automatic image conversion reaches the parser when DecoderOptions.ColorProfileHandling is Convert; the default Preserve mode avoids that conversion path. The demonstrated impact is memory pressure and input-validation failure, not unhandled process termination. This issue is fixed in version 4.1.2.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-06T18:16:53.100Z",
"pubdate": "2026-10-06T18:16:53.100Z",
"executiveSummary": "ImageSharp versions 1.0.0-beta0001 through 4.1.2 are susceptible to a memory exhaustion vulnerability within the ICC (International Color Consortium) profile parsing logic. The vulnerability arises from improper input validation where allocation sizes are derived directly from attacker-supplied metadata before verifying the integrity or contents of the profile.\nThis flaw allows a remote attacker to trigger excessive memory allocations by providing a maliciously crafted, truncated ICC profile. In version 4, the risk is heightened when DecoderOptions.ColorProfileHandling is explicitly set to Convert, as this triggers the vulnerable parsing path. The default behavior, Preserve, mitigates this exposure.\nThe primary impact is significant memory pressure, potentially leading to denial-of-service conditions through resource exhaustion. Successful exploitation requires the application to process a tainted image file containing a malformed ICC profile. The vulnerability does not appear to facilitate arbitrary code execution but poses a risk to system stability by inducing application-level resource depletion.",
"technicalDetails": "The vulnerability resides in the ICC profile parsing module of ImageSharp, specifically affecting how the library interprets channel and grid dimensions within an ICC Color Look-Up Table (CLUT). The flaw is rooted in a failure to validate the consistency between declared profile dimensions and the actual byte-length of the provided data buffer.\nDuring the parsing process, specifically within the IccDataReader.ReadClutF32 function, the library calculates memory allocation sizes based on attacker-controlled inputs representing channel and grid dimensions. Because these dimensions are trusted before the corresponding data is validated, an attacker can supply a small, truncated ICC profile that claims to contain massive, non-existent multidimensional array structures.\nThe exploitation flow is as follows: 1) An attacker crafts a malicious image file containing a truncated or malformed ICC profile metadata header. 2) The image is submitted to an application using ImageSharp. 3) If the application configuration uses DecoderOptions.ColorProfileHandling set to Convert, the library invokes the vulnerable parsing routine. 4) The parser reads the inflated channel/grid dimensions and allocates a large float array or a complex jagged data structure in memory. 5) This leads to a rapid consumption of heap memory proportional to the attacker-defined values, causing severe memory pressure.\nIn earlier versions, the public IccProfile.Entries parsing path is also affected, leading to similar heap-based resource exhaustion. The vulnerability is characterized by an absence of sufficient bounds checking or validation that the profile length matches the requirements imposed by the declared header dimensions. By manipulating the profile entry metadata, an attacker forces the .NET runtime to attempt large allocations, which can result in input-validation failure or significant performance degradation.\nWhile the description notes that this typically results in memory pressure rather than unhandled process termination, the cumulative effect of repeated requests could force an OutOfMemoryException or trigger aggressive garbage collection cycles, effectively causing a denial-of-service for the processing service. No specific authentication or elevated privileges are required, as the vector is the processing of user-supplied image input."
}