CVE-2026-106117
Received Received - Intake

Heap Overflow in ImageSharp TIFF Decoding

Vulnerability report for CVE-2026-106117, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

ImageSharp is a 2D graphics library. From 3.0.0 until 4.1.1, decoding a strip TIFF using CCITT Group 3 or Modified Huffman compression can pass attacker-expanded runs to BitWriterUtils.WriteBits without first checking the current row width. T4TiffCompression.WritePixelRun can accumulate oversized makeup-code runs, and ModifiedHuffmanTiffCompression.Decompress validates the width only after writing. The unchecked writes can overflow the strip buffer, corrupt heap memory, and terminate the process. This strip-path vulnerability is distinct from the tiled decompressor-width mismatch. This issue is fixed in version 4.1.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
SixLabors ImageSharp >= 3.0.0, < 4.1.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

ImageSharp is a 2D graphics library. A vulnerability exists in versions 3.0.0 to 4.1.1 where decoding a strip TIFF using CCITT Group 3 or Modified Huffman compression can lead to buffer overflows. Attackers can exploit this by passing oversized runs to BitWriterUtils.WriteBits without checking row width, causing heap memory corruption and process termination.

Detection Guidance

This vulnerability affects ImageSharp versions 3.0.0 to 4.1.0 when processing TIFF files with CCITT Group 3 or Modified Huffman compression. Detection requires checking installed ImageSharp versions and inspecting TIFF file processing in applications. No specific commands are provided in the context.

Impact Analysis

This vulnerability can cause denial-of-service by crashing the application due to heap memory corruption. It may also allow attackers to execute arbitrary code if they can craft malicious TIFF files, potentially leading to further system compromise.

Compliance Impact

This vulnerability primarily causes memory corruption and process termination due to buffer overflows during TIFF image decoding. It does not directly impact data privacy or confidentiality, which are key concerns for GDPR and HIPAA. However, if exploited in a system processing sensitive data, it could lead to denial-of-service conditions, potentially disrupting compliance with availability requirements in these regulations.

Mitigation Strategies

Upgrade ImageSharp to version 4.1.1 or later to address the vulnerability. Review applications using ImageSharp for TIFF processing and ensure no untrusted files are processed until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106117. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart