CVE-2026-106116
Received Received - Intake

Memory Corruption in ImageSharp via Malformed BigTIFF

Vulnerability report for CVE-2026-106116, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, ExifReader.ReadValues64 trusts the 64-bit BigTIFF IFD entry count and iterates once per declared entry. When fewer than 20 bytes remain, ExifReader.ReadValue64 returns without advancing the stream or terminating the outer loop, so a small malformed BigTIFF can keep one decoder thread executing for an attacker-controlled duration. This report does not claim worker-pool exhaustion. This issue is fixed in version 4.1.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
SixLabors ImageSharp >= 2.0.0, < 4.1.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-835 The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

ImageSharp is a 2D graphics library. The vulnerability exists in versions 2.0.0 to 4.1.2 where ExifReader.ReadValues64 incorrectly processes BigTIFF IFD entries. A malformed BigTIFF file with fewer than 20 bytes can cause the decoder thread to execute for an attacker-controlled duration without proper termination.

Detection Guidance

This vulnerability is specific to ImageSharp library versions 2.0.0 to 4.1.1. Detection involves checking installed versions of ImageSharp in your applications or dependencies. Use commands like 'dotnet list package' for .NET projects or inspect package.json for Node.js projects to identify affected versions.

Impact Analysis

This vulnerability can cause denial-of-service by consuming excessive CPU resources in a single thread. Attackers could exploit it to slow down or crash applications using affected versions of ImageSharp.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it is a denial-of-service issue in a graphics library. However, if exploited in a system processing sensitive data, it could lead to service disruption, potentially impacting availability requirements under GDPR or HIPAA.

Mitigation Strategies

Upgrade ImageSharp to version 4.1.2 or later immediately. If using NuGet, run 'dotnet add package SixLabors.ImageSharp --version 4.1.2'. For other package managers, update the dependency to the patched version. Remove any unused BigTIFF image processing code temporarily if immediate upgrade is not feasible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106116. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart