CVE-2026-106110
Received Received - Intake

Buffer Overflow in ImageSharp TIFF Encoder

Vulnerability report for CVE-2026-106110, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Group 3 encoder allocates an undersized compressed-data buffer for narrow 1-bit images. TiffCcittCompressor.Initialize does not reserve enough space for the row data and T4 end-of-line codes, and T4BitCompressor.CompressStrip reaches unchecked writes when TiffCompression.CcittGroup3Fax is selected directly or inherited from decoded TIFF metadata. An attacker-controlled encode or decode-and-re-encode flow can write beyond the logical output span, corrupt process memory, and terminate the process. This issue is fixed in version 4.1.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
SixLabors ImageSharp >= 2.0.0, < 4.1.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in ImageSharp, a 2D graphics library. It involves an undersized buffer allocation in the TIFF CCITT Group 3 encoder for narrow 1-bit images. The encoder does not reserve enough space for row data and end-of-line codes, leading to potential memory corruption when processing certain TIFF files.

Detection Guidance

This vulnerability affects ImageSharp versions 2.0.0 to 4.1.1 when processing TIFF images with CCITT Group 3 encoding. To detect it, check installed ImageSharp versions and scan for TIFF files using affected encoders. No specific commands are provided in the context.

Impact Analysis

An attacker could exploit this flaw by providing a specially crafted TIFF image. This could corrupt memory, crash the application, or potentially allow arbitrary code execution if the vulnerable library is used in a server or application processing untrusted input.

Compliance Impact

This vulnerability could lead to denial-of-service or data corruption in systems handling sensitive data. For GDPR, it may impact availability of services processing personal data. For HIPAA, it could affect integrity of medical imaging systems. Organizations must ensure affected libraries are updated to mitigate risks.

Mitigation Strategies

Upgrade ImageSharp to version 4.1.2 or later to address the buffer overflow issue. Remove or restrict access to TIFF files using CCITT Group 3 encoding until patched. Monitor for crashes during image processing as a potential indicator of exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106110. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart