PT-2026-106827 · Unknown · Imagesharp

CVE-2026-106110

·

Published

2026-10-06

·

Updated

2026-10-07

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ImageSharp versions 2.0.0 through 4.1.1
Description The TIFF CCITT Group 3 encoder allocates an undersized compressed-data buffer for narrow 1-bit images. The TiffCcittCompressor.Initialize function fails to reserve sufficient space for row data and T4 end-of-line codes. Consequently, the T4BitCompressor.CompressStrip function performs unchecked writes when TiffCompression.CcittGroup3Fax is selected directly or inherited from decoded TIFF metadata. An attacker-controlled encode or decode-and-re-encode flow can lead to writing beyond the logical output span, resulting in process memory corruption and process termination.
Recommendations Update to version 4.1.2.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106110
GHSA-J9GM-C75J-XC9Q

Affected Products

Imagesharp