Description
ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, ExifReader.ReadValues64 trusts the 64-bit BigTIFF IFD entry count and iterates once per declared entry. When fewer than 20 bytes remain, ExifReader.ReadValue64 returns without advancing the stream or terminating the outer loop, so a small malformed BigTIFF can keep one decoder thread executing for an attacker-controlled duration. This report does not claim worker-pool exhaustion. This issue is fixed in version 4.1.2.
Published: 2026-10-06
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service (CPU and thread exhaustion)
Action: Immediate Patch
AI Analysis

Impact

A bug in ImageSharp’s ExifReader.ReadValues64 trusts the 64‑bit BigTIFF IFD entry count and iterates once per declared entry. When fewer than 20 bytes remain, the reader returns without advancing the stream or breaking the outer loop, which can cause a decoder thread to execute for an attacker‑controlled duration. This loop consumes CPU and keeps a worker thread busy, creating a resource exhaustion condition that can degrade or deny service. The weakness is identified as CWE‑835, an infinite loop flaw.

Affected Systems

SixLabors ImageSharp libraries from version 2.0.0 through 4.1.1 are affected. Applications that process TIFF or BigTIFF files containing Exif metadata and rely on these ImageSharp releases are vulnerable. The issue is fixed in ImageSharp version 4.1.2 and later.

Risk and Exploitability

The CVSS score of 5.3 reflects a moderate impact. No EPSS data is available, and the vulnerability is not currently listed in CISA’s KEV catalog. An attacker who can supply a crafted BigTIFF file can cause a decoder thread to enter a non‑progressing loop, which may be executed over the network if the application accepts user‑uploaded images or locally if untrusted files are read. The likely attack vector is inferred to be remote via image upload, but the vulnerability can also be triggered by local file usage. The attack requires that the vulnerable library parse the file, so the practical exploitation vector is likely remote via image upload but local file usage is also possible.

Generated by OpenCVE AI on October 6, 2026 at 20:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to ImageSharp 4.1.2 or a later version that contains the patch.
  • If an upgrade is not immediately possible, configure the application to reject or skip processing of files that contain BigTIFF Exif IFD counts greater than the supported range, effectively disabling the vulnerable parsing path.
  • For critical environments, isolate image decoding in a sandboxed process or container with restricted CPU and thread limits and monitor for unusually long decoding operations.

Generated by OpenCVE AI on October 6, 2026 at 20:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Description ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, ExifReader.ReadValues64 trusts the 64-bit BigTIFF IFD entry count and iterates once per declared entry. When fewer than 20 bytes remain, ExifReader.ReadValue64 returns without advancing the stream or terminating the outer loop, so a small malformed BigTIFF can keep one decoder thread executing for an attacker-controlled duration. This report does not claim worker-pool exhaustion. This issue is fixed in version 4.1.2.
Title ImageSharp: BigTIFF IFD count can keep a decoder thread in a non-progressing loop
Weaknesses CWE-835
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T18:21:55.088Z

Reserved: 2026-10-06T15:33:55.333Z

Link: CVE-2026-106116

cve-icon Vulnrichment

Updated: 2026-10-06T18:21:10.476Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T18:16:53.400

Modified: 2026-10-06T20:03:40.690

Link: CVE-2026-106116

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T20:15:05Z

Weaknesses
  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')