Impact
The vulnerability in ImageSharp allows an attacker to influence the allocation size for ICC color lookup tables by specifying large channel and grid dimensions. The library calculates these sizes before verifying that the profile actually contains them, resulting in an over‑allocation of memory and input‑validation failure. While the flaw does not cause an immediate crash, the excessive memory consumption can degrade performance or exhaust system resources, effectively leading to a denial of service.
Affected Systems
All releases of SixLabors ImageSharp from 1.0.0‑beta0001 to 4.1.2 are affected. The issue is fixed in version 4.1.2 and later.
Risk and Exploitability
The CVSS score is 5.3, indicating moderate severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV. Attackers who can supply a crafted ICC profile with exaggerated channel or grid sizes can trigger the oversized allocation when the library auto‑converts profiles (DecoderOptions.ColorProfileHandling set to Convert). The default Preserve mode avoids this path, but if not configured, the risk of memory pressure remains. No privilege escalation or remote code execution is possible; the impact is limited to resource exhaustion.
OpenCVE Enrichment