PT-2026-106839 · Unknown · Imagesharp

CVE-2026-106118

·

Published

2026-10-06

·

Updated

2026-10-07

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ImageSharp versions 3.0.0 through 4.1.0
Description In the tiled TIFF decoding process, a destination buffer is allocated using TileWidth, but the TiffDecompressorsFactory.Create function constructs T4, T6, and Modified Huffman decompressors using the full frame width. Consequently, the TiffDecoderCore.DecodeTilesChunky function can direct frame-width fax scanlines into a tile-width buffer when TileWidth is smaller than ImageWidth. This mismatch leads to attacker-controlled out-of-bounds writes, heap corruption, and process termination.
Recommendations Update to version 4.1.1.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106118
GHSA-V76P-62QX-WWQ2

Affected Products

Imagesharp