PT-2026-106829 · Unknown · Imagesharp

CVE-2026-106112

·

Published

2026-10-06

·

Updated

2026-10-07

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ImageSharp versions 4.0.0 through 4.1.1
Description An issue exists in the ICC LUT16 conversion process where the system accepts more than four output channels, despite ClutCalculator.Calculate() and LutEntryCalculator.CalculateLut() storing values in Vector4. When DecoderOptions.ColorProfileHandling is set to Convert, a malformed embedded profile can cause interpolation and output-LUT operations to write data beyond the four-float destination, leading to memory corruption and process termination. This does not occur in the default Preserve mode.
Recommendations Update to version 4.1.2. Avoid setting DecoderOptions.ColorProfileHandling to Convert when processing untrusted profiles.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106112
GHSA-FFP7-56PQ-64MR

Affected Products

Imagesharp