Medium severity5.3NVD Advisory· Published Jul 22, 2024· Updated Jun 17, 2026
CVE-2024-41132
CVE-2024-41132
Description
ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. All users are advised to upgrade to v3.1.5 or v2.1.9.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
SixLabors.ImageSharpNuGet | < 2.1.9 | 2.1.9 |
SixLabors.ImageSharpNuGet | >= 3.0.0, < 3.1.5 | 3.1.5 |
Affected products
3cpe:2.3:a:sixlabors:imagesharp:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sixlabors:imagesharp:*:*:*:*:*:*:*:*range: >=2.1.0,<2.1.9
- (no CPE)range: < 2.1.9
Patches
Vulnerability mechanics
References
11- github.com/SixLabors/ImageSharp/commit/59de13c8cc47f2b402e2c43aa7024511d029d515nvdPatchWEB
- github.com/SixLabors/ImageSharp/commit/9816ca45016c5d3859986f3c600e8934bc450a56nvdPatchWEB
- github.com/SixLabors/ImageSharp/commit/b496109051cc39feee1f6cde48fca6481de17f9anvdPatchWEB
- github.com/SixLabors/ImageSharp/security/advisories/GHSA-qxrv-gp6x-rc23nvdVendor AdvisoryWEB
- github.com/advisories/GHSA-qxrv-gp6x-rc23ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-41132ghsaADVISORY
- docs.sixlabors.com/articles/imagesharp.web/processingcommands.htmlnvdProductWEB
- docs.sixlabors.com/articles/imagesharp/security.htmlnvdProductWEB
- github.com/SixLabors/ImageSharp/pull/2759nvdIssue TrackingWEB
- github.com/SixLabors/ImageSharp/pull/2764nvdIssue TrackingWEB
- github.com/SixLabors/ImageSharp/pull/2770nvdIssue TrackingWEB
News mentions
0No linked articles in our index yet.