PT-2026-106838 · Unknown · Imagesharp

CVE-2026-106117

·

Published

2026-10-06

·

Updated

2026-10-07

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ImageSharp versions 3.0.0 through 4.1.0
Description Decoding a strip TIFF using CCITT Group 3 or Modified Huffman compression allows the passing of attacker-expanded runs to BitWriterUtils.WriteBits without verifying the current row width. Specifically, T4TiffCompression.WritePixelRun can accumulate oversized makeup-code runs, and ModifiedHuffmanTiffCompression.Decompress performs width validation only after the writing process. These unchecked writes can lead to a strip buffer overflow, resulting in heap memory corruption and process termination.
Recommendations Update to version 4.1.1.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106117
GHSA-JJ3Q-CWQJ-842R

Affected Products

Imagesharp