Description
ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, decoding an attacker-supplied 32-bit floating-point TIFF as Image<HalfVector4> and applying HistogramEqualization can produce a non-finite or out-of-range luminance in ColorNumerics.GetBT709Luminance. GrayscaleLevelsRowOperation.Invoke uses the resulting value as an unchecked histogram offset, causing an unsafe out-of-range access and process termination. Adaptive Histogram Equalization and AutoLevel are not affected by this report. This issue is fixed in version 4.1.2.
Published: 2026-10-06
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

HistogramEqualization in ImageSharp uses an unvalidated luminance as an unchecked histogram index, which can result in a non‑finite or out‑of‑range value. When an attacker supplies a 32‑bit floating‑point TIFF and invokes this filter, the library performs an unsafe read based on that value, causing a process crash. The outcome is a denial of service to the application hosting the library.

Affected Systems

The vulnerability affects SixLabors ImageSharp versions from 2.0.0 up to and including 4.1.2. All deployments that use ImageSharp to process TIFF images with HistogramEqualization are at risk.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity risk. No EPSS score is available, and the defect is not listed in the CISA KEV catalog, but the lack of input validation makes exploitation straightforward if an application accepts untrusted images. The attack would be performed remotely by providing a crafted TIFF file to a service that uses the vulnerable library.

Generated by OpenCVE AI on October 6, 2026 at 19:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade SixLabors ImageSharp to version 4.1.2 or newer
  • Avoid using HistogramEqualization on attacker‑supplied TIFF images if an update is not feasible
  • Implement input validation to ensure luminance values are finite before processing or restrict usage of the affected functions

Generated by OpenCVE AI on October 6, 2026 at 19:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Description ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, decoding an attacker-supplied 32-bit floating-point TIFF as Image<HalfVector4> and applying HistogramEqualization can produce a non-finite or out-of-range luminance in ColorNumerics.GetBT709Luminance. GrayscaleLevelsRowOperation.Invoke uses the resulting value as an unchecked histogram offset, causing an unsafe out-of-range access and process termination. Adaptive Histogram Equalization and AutoLevel are not affected by this report. This issue is fixed in version 4.1.2.
Title ImageSharp: HistogramEqualization uses an unvalidated luminance as an unchecked histogram index
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T17:47:17.503Z

Reserved: 2026-10-06T15:33:55.333Z

Link: CVE-2026-106113

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T18:16:52.953

Modified: 2026-10-06T20:03:40.690

Link: CVE-2026-106113

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T20:00:06Z

Weaknesses