Sceawere

Vulnerability Detail

CVE-2026-106115UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

ImageSharp Out-of-Bounds Memory Corruption

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
7h ago
Vendor
SixLabors
Product
ImageSharp
Attack Type
CWE-787: Out-of-bounds Write
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

ImageSharp is a 2D graphics library. From 2.1.0 until 4.1.2, the TIFF CCITT Group 4 encoder allocates Width times rowsPerStrip bytes even though T6BitCompressor.CompressStrip can emit encoded row data and two 12-bit end-of-facsimile-block codes beyond that capacity. TiffCcittCompressor.WriteCode performs unchecked writes, and a decode-and-re-encode flow can inherit TiffCompression.CcittGroup4Fax and one-bit metadata from attacker-supplied input. The resulting out-of-bounds writes can corrupt memory and terminate the process. This issue is fixed in version 4.1.2.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-06T18:16:53.250Z",
  "pubdate": "2026-10-06T18:16:53.250Z",
  "executiveSummary": "ImageSharp versions 2.1.0 through 4.1.2 are susceptible to an out-of-bounds (OOB) memory corruption vulnerability originating in the TIFF CCITT Group 4 encoder.\nThe vulnerability occurs due to an insufficient buffer allocation strategy where the allocated memory capacity does not account for the additional metadata and end-of-block codes appended during the compression process.\nAn attacker can exploit this flaw by providing a crafted input file that, when processed through a decode-and-re-encode workflow using the CcittGroup4Fax compression option, triggers unchecked write operations in the TiffCcittCompressor.WriteCode function.\nThe potential impact includes process termination, denial of service (DoS), and potential memory corruption that could theoretically be leveraged for arbitrary code execution depending on the host process memory layout.\nSuccessful exploitation requires the application to process attacker-controlled image data with specific compression settings.\nThis vulnerability highlights a critical failure in bounds checking during stream processing, necessitating an immediate upgrade to version 4.1.2 or later to ensure proper buffer management and input sanitization.",
  "technicalDetails": "The root cause of this vulnerability lies in an improper buffer size calculation within the TIFF CCITT Group 4 encoder. During the image compression phase, the encoder allocates memory based on the product of the image Width and the rowsPerStrip parameter. However, the internal T6BitCompressor.CompressStrip method emits encoded row data alongside supplementary 12-bit end-of-facsimile-block (EOFB) markers that exceed the pre-allocated buffer capacity.\nThe vulnerability is primarily located in the TiffCcittCompressor.WriteCode function, which performs write operations to the destination buffer without performing adequate bounds validation. Because the encoder assumes the allocated memory is sufficient for the compressed stream, the subsequent inclusion of the end-of-facsimile-block codes triggers a write operation past the end of the allocated heap buffer.\nThe attack flow involves an attacker supplying a malformed or specifically crafted image file. If the application environment performs a decode-and-re-encode workflow, the attacker can force the engine to utilize the TiffCompression.CcittGroup4Fax compression algorithm. By manipulating the one-bit metadata and image dimensions within the input file, the attacker forces the encoder to initialize an undersized buffer. As the T6BitCompressor processes the data, the unchecked write operations occur sequentially as the compressor appends compressed bits and the trailing 12-bit EOFB codes.\nSince the write operation is unchecked, the trailing bytes overflow the allocated segment, leading to heap memory corruption. In most managed environments, this corruption leads to an immediate access violation or memory management exception, resulting in a process crash (DoS). In more complex scenarios, this OOB write could overwrite adjacent heap objects, potentially altering control flow or application state if object references are overwritten.\nAffected versions are identified as 2.1.0 up to and including 4.1.2. The vulnerability exists within the ImageSharp graphics library's internal TIFF codec implementation. Exploitation does not require authentication to the target system, provided that the application provides a public or semi-public endpoint that accepts and processes image uploads, thereby facilitating the processing of malicious payloads.\nThis vulnerability is exacerbated in high-throughput environments where automated image processing pipelines ingest untrusted user data, as the transition through the decode-and-re-encode cycle is a common pattern in web-based image manipulation services."
}
CVE-2026-106115: ImageSharp Out-of-Bounds Memory Corruption (HIGH Severity, CVSS: 7.5) | Sceawere