Medium severity5.9NVD Advisory· Published Oct 6, 2026· Updated Oct 6, 2026
CVE-2026-106111
CVE-2026-106111
Description
ImageSharp is a 2D graphics library. From 4.0.0 until 4.1.2, ExrBaseDecompressor.UndoZipCompression accepts a nonempty ZIP or ZIPS inflate result that is shorter than the EXR block's required size. ZipExrCompression.Decompress reconstructs the returned prefix while ExrDecoderCore processes the full expected block from a buffer obtained through Configuration.Default, allowing bytes retained from a completed prior ImageSharp operation to appear in decoded pixels. Applications that expose pixels or output from the later attacker-controlled EXR decode can disclose process-local image data. This issue is fixed in version 4.1.2.
Affected products
1- Range: 4.0.0 - 4.1.1
Patches
Vulnerability mechanics
References
5- github.com/SixLabors/ImageSharp/commit/3c43cf583fdd98eff0f451397affaa31c6a2e6b1nvd
- github.com/SixLabors/ImageSharp/commit/6ed2a275217d39301e76df42acec2a9533b39d2bnvd
- github.com/SixLabors/ImageSharp/pull/3187nvd
- github.com/SixLabors/ImageSharp/releases/tag/v4.1.2nvd
- github.com/SixLabors/ImageSharp/security/advisories/GHSA-4q3p-rj5x-xv7pnvd
News mentions
0No linked articles in our index yet.