CVE-2026-106114
Received Received - Intake

Memory Corruption in ImageSharp ICC Profile Parsing

Vulnerability report for CVE-2026-106114, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

ImageSharp is a 2D graphics library. From 1.0.0-beta0001 until 4.1.2, ICC CLUT parsing calculates allocation sizes from attacker-declared channel and grid dimensions before confirming that the profile contains the declared values. IccDataReader.ReadClutF32 can request a large float array, and earlier public IccProfile.Entries parsing paths can allocate a large jagged representation, from a short truncated profile. In version 4, automatic image conversion reaches the parser when DecoderOptions.ColorProfileHandling is Convert; the default Preserve mode avoids that conversion path. The demonstrated impact is memory pressure and input-validation failure, not unhandled process termination. This issue is fixed in version 4.1.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
SixLabors ImageSharp >= 1.0.0-beta0001, < 4.1.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-789 The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

ImageSharp versions between 1.0.0-beta0001 and 4.1.2 have a flaw in ICC CLUT parsing where allocation sizes are calculated from attacker-declared channel and grid dimensions without verifying if the profile contains those values. This leads to potential memory pressure and input-validation failures.

Detection Guidance

This vulnerability is specific to ImageSharp library versions between 1.0.0-beta0001 and 4.1.2. Detection involves checking installed versions of ImageSharp in your applications or dependencies. Use commands like 'dotnet list package' for .NET projects or inspect package.json for Node.js projects to identify affected versions.

Impact Analysis

The vulnerability can cause memory pressure and input-validation failures in applications using affected ImageSharp versions. It may lead to degraded performance or crashes due to excessive memory usage.

Compliance Impact

This vulnerability primarily causes memory pressure and input-validation failure, which could lead to denial-of-service conditions or unexpected behavior in applications using ImageSharp. While it does not directly violate GDPR or HIPAA, such disruptions may impact system availability and integrity, potentially affecting compliance with requirements for secure and reliable data processing.

Mitigation Strategies

Upgrade ImageSharp to version 4.1.2 or later immediately. If using automatic image conversion, set DecoderOptions.ColorProfileHandling to Preserve to avoid the vulnerable parsing path. Review and update all dependencies to ensure no outdated versions remain in use.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106114. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart