Impact
HistogramEqualization in ImageSharp uses an unvalidated luminance as an unchecked histogram index, which can result in a non‑finite or out‑of‑range value. When an attacker supplies a 32‑bit floating‑point TIFF and invokes this filter, the library performs an unsafe read based on that value, causing a process crash. The outcome is a denial of service to the application hosting the library.
Affected Systems
The vulnerability affects SixLabors ImageSharp versions from 2.0.0 up to and including 4.1.2. All deployments that use ImageSharp to process TIFF images with HistogramEqualization are at risk.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity risk. No EPSS score is available, and the defect is not listed in the CISA KEV catalog, but the lack of input validation makes exploitation straightforward if an application accepts untrusted images. The attack would be performed remotely by providing a crafted TIFF file to a service that uses the vulnerable library.
OpenCVE Enrichment