Description
ImageSharp is a 2D graphics library. From 1.0.0-beta0001 until 4.1.2, ICC CLUT parsing calculates allocation sizes from attacker-declared channel and grid dimensions before confirming that the profile contains the declared values. IccDataReader.ReadClutF32 can request a large float array, and earlier public IccProfile.Entries parsing paths can allocate a large jagged representation, from a short truncated profile. In version 4, automatic image conversion reaches the parser when DecoderOptions.ColorProfileHandling is Convert; the default Preserve mode avoids that conversion path. The demonstrated impact is memory pressure and input-validation failure, not unhandled process termination. This issue is fixed in version 4.1.2.
Published: 2026-10-06
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service via Memory Over-Allocation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in ImageSharp allows an attacker to influence the allocation size for ICC color lookup tables by specifying large channel and grid dimensions. The library calculates these sizes before verifying that the profile actually contains them, resulting in an over‑allocation of memory and input‑validation failure. While the flaw does not cause an immediate crash, the excessive memory consumption can degrade performance or exhaust system resources, effectively leading to a denial of service.

Affected Systems

All releases of SixLabors ImageSharp from 1.0.0‑beta0001 to 4.1.2 are affected. The issue is fixed in version 4.1.2 and later.

Risk and Exploitability

The CVSS score is 5.3, indicating moderate severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV. Attackers who can supply a crafted ICC profile with exaggerated channel or grid sizes can trigger the oversized allocation when the library auto‑converts profiles (DecoderOptions.ColorProfileHandling set to Convert). The default Preserve mode avoids this path, but if not configured, the risk of memory pressure remains. No privilege escalation or remote code execution is possible; the impact is limited to resource exhaustion.

Generated by OpenCVE AI on October 6, 2026 at 19:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade SixLabors ImageSharp to version 4.1.2 or later
  • If an upgrade is not feasible, set DecoderOptions.ColorProfileHandling to Preserve to prevent automatic ICC profile conversion
  • Validate ICC profiles before passing them to ImageSharp or restrict image input to trusted sources

Generated by OpenCVE AI on October 6, 2026 at 19:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Description ImageSharp is a 2D graphics library. From 1.0.0-beta0001 until 4.1.2, ICC CLUT parsing calculates allocation sizes from attacker-declared channel and grid dimensions before confirming that the profile contains the declared values. IccDataReader.ReadClutF32 can request a large float array, and earlier public IccProfile.Entries parsing paths can allocate a large jagged representation, from a short truncated profile. In version 4, automatic image conversion reaches the parser when DecoderOptions.ColorProfileHandling is Convert; the default Preserve mode avoids that conversion path. The demonstrated impact is memory pressure and input-validation failure, not unhandled process termination. This issue is fixed in version 4.1.2.
Title ImageSharp: ICC CLUT parsing allocates from unvalidated channel and grid dimensions
Weaknesses CWE-789
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T19:44:26.694Z

Reserved: 2026-10-06T15:33:55.333Z

Link: CVE-2026-106114

cve-icon Vulnrichment

Updated: 2026-10-06T19:44:22.943Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T18:16:53.100

Modified: 2026-10-06T20:17:17.587

Link: CVE-2026-106114

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T20:00:06Z

Weaknesses
  • CWE-789

    Memory Allocation with Excessive Size Value