PT-2026-106827 · Unknown · Imagesharp
CVE-2026-106110
·
Published
2026-10-06
·
Updated
2026-10-07
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
ImageSharp versions 2.0.0 through 4.1.1
Description
The TIFF CCITT Group 3 encoder allocates an undersized compressed-data buffer for narrow 1-bit images. The
TiffCcittCompressor.Initialize function fails to reserve sufficient space for row data and T4 end-of-line codes. Consequently, the T4BitCompressor.CompressStrip function performs unchecked writes when TiffCompression.CcittGroup3Fax is selected directly or inherited from decoded TIFF metadata. An attacker-controlled encode or decode-and-re-encode flow can lead to writing beyond the logical output span, resulting in process memory corruption and process termination.Recommendations
Update to version 4.1.2.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Imagesharp