Description
ImageSharp is a 2D graphics library. From 2.1.0 until 4.1.2, the TIFF CCITT Group 4 encoder allocates Width times rowsPerStrip bytes even though T6BitCompressor.CompressStrip can emit encoded row data and two 12-bit end-of-facsimile-block codes beyond that capacity. TiffCcittCompressor.WriteCode performs unchecked writes, and a decode-and-re-encode flow can inherit TiffCompression.CcittGroup4Fax and one-bit metadata from attacker-supplied input. The resulting out-of-bounds writes can corrupt memory and terminate the process. This issue is fixed in version 4.1.2.
Published: 2026-10-06
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Unbounded Memory Write Leading to Potential Crash
Action: Patch
AI Analysis

Impact

The TIFF CCITT Group 4 encoder in ImageSharp allocates a fixed buffer based on image width and rows per strip, but the compressor can emit more data than this buffer holds. As a result, the WriteCode routine performs unchecked writes that may overflow the buffer and corrupt adjacent memory. Attacker-supplied TIFF files that exercise this path can trigger the out-of-bounds writes, potentially causing the process to crash due to memory corruption. The flaw is strictly related to the encoder's buffer management and is classified as an out-of-bounds write

Affected Systems

All deployments of SixLabors ImageSharp from version 2.1.0 up to, but not including, 4.1.2 are vulnerable. Any application that uses ImageSharp to decode or re-encode TIFF images with CCITT Group 4 compression is affected. The vulnerability has been resolved in ImageSharp 4.1.2 and later releases

Risk and Exploitability

The CVSS score of 7.5 places this issue in the medium-to-high severity range, indicating significant impact but not guaranteeing immediate exploitability. EPSS data is currently unavailable, and the vulnerability has not yet been listed in the CISA KEV catalog. Because the flaw is triggered by processing a crafted TIFF file, the attack vector is most likely local or remote via a trusted input channel. An attacker would need to supply a malicious TIFF to an application that processes user data, making the vulnerability exploitable in environments that accept unverified image uploads. Exfiltration cannot occur directly, and the effect is limited to process termination via memory corruption.

Generated by OpenCVE AI on October 6, 2026 at 20:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade imageSharp to version 4.1.2 or later, which includes the encoding buffer fix
  • If an upgrade cannot be performed immediately, restrict the processing of TIFF files to trusted sources and validate file integrity before decoding
  • As an interim workaround, disable CCITT Group 4 compression in applications that use imageSharp, or use an alternative imaging library for this compression type

Generated by OpenCVE AI on October 6, 2026 at 20:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Description ImageSharp is a 2D graphics library. From 2.1.0 until 4.1.2, the TIFF CCITT Group 4 encoder allocates Width times rowsPerStrip bytes even though T6BitCompressor.CompressStrip can emit encoded row data and two 12-bit end-of-facsimile-block codes beyond that capacity. TiffCcittCompressor.WriteCode performs unchecked writes, and a decode-and-re-encode flow can inherit TiffCompression.CcittGroup4Fax and one-bit metadata from attacker-supplied input. The resulting out-of-bounds writes can corrupt memory and terminate the process. This issue is fixed in version 4.1.2.
Title ImageSharp: TIFF CCITT T6 encoder writes beyond an undersized output buffer
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T17:50:15.754Z

Reserved: 2026-10-06T15:33:55.333Z

Link: CVE-2026-106115

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T18:16:53.250

Modified: 2026-10-06T20:03:40.690

Link: CVE-2026-106115

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T20:15:05Z

Weaknesses