CVE-2026-106112
Received Received - Intake

Memory Corruption in ImageSharp via ICC LUT16 Conversion

Vulnerability report for CVE-2026-106112, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

ImageSharp is a 2D graphics library. From 4.0.0 until 4.1.2, ICC LUT16 conversion accepts more than four output channels even though ClutCalculator.Calculate and LutEntryCalculator.CalculateLut store intermediate and output values in Vector4. When DecoderOptions.ColorProfileHandling is set to Convert, a malformed embedded profile can direct interpolation and output-LUT operations to write one float per declared channel beyond the four-float destination. This can corrupt memory and terminate the process; the default Preserve mode does not run ICC conversion. This issue is fixed in version 4.1.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
SixLabors ImageSharp >= 4.0.0, < 4.1.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

ImageSharp is a 2D graphics library. A vulnerability exists in versions 4.0.0 to 4.1.2 where ICC LUT16 conversion can accept more than four output channels. This leads to memory corruption when DecoderOptions.ColorProfileHandling is set to Convert, as intermediate values are stored in Vector4 but the process writes beyond the four-float destination. The default Preserve mode avoids this issue.

Detection Guidance

Detection involves checking for ImageSharp versions between 4.0.0 and 4.1.2 with DecoderOptions.ColorProfileHandling set to Convert. Inspect application dependencies and configuration files for ImageSharp usage. No specific commands are provided in the context.

Impact Analysis

This vulnerability can cause memory corruption and terminate the process when processing malformed embedded profiles with specific settings. It may lead to application crashes or unexpected behavior during image processing tasks.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it is a memory corruption issue in a graphics library that could lead to process termination. No evidence suggests data exposure or unauthorized access that would violate these regulations.

Mitigation Strategies

Upgrade ImageSharp to version 4.1.2 or later. If using DecoderOptions.ColorProfileHandling set to Convert, switch to Preserve mode to avoid ICC conversion. Review and update all ImageSharp dependencies in your projects.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106112. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart