CVE-2026-106112: CWE-787: Out-of-bounds Write in SixLabors ImageSharp
Description
ImageSharp is a 2D graphics library. From 4.0.0 until 4.1.2, ICC LUT16 conversion accepts more than four output channels even though ClutCalculator.Calculate and LutEntryCalculator.CalculateLut store intermediate and output values in Vector4. When DecoderOptions.ColorProfileHandling is set to Convert, a malformed embedded profile can direct interpolation and output-LUT operations to write one float per declared channel beyond the four-float destination. This can corrupt memory and terminate the process; the default Preserve mode does not run ICC conversion. This issue is fixed in version 4.1.2.
CVSS v3.1
Score 7.5high
Affected software
SixLabors
ImageSharp
pkg:nuget/sixlabors.imagesharpRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
ImageSharp versions >=4.0.0 and <4.1.2 contain an out-of-bounds write vulnerability (CWE-787) in the ICC LUT16 conversion process. The issue arises because ClutCalculator.Calculate and LutEntryCalculator.CalculateLut store intermediate and output values in Vector4, which supports only four floats, but the conversion accepts more than four output channels. When DecoderOptions.ColorProfileHandling is set to Convert, a malformed embedded ICC profile can cause interpolation and output-LUT operations to write one float per declared channel beyond the four-float destination buffer. This can lead to memory corruption and process termination. The vulnerability is addressed in ImageSharp version 4.1.2.
Potential Impact
This vulnerability can cause memory corruption leading to application crashes (denial of service) when processing malformed embedded ICC profiles with the ColorProfileHandling option set to Convert. There is no indication of confidentiality or integrity impact. No known exploits are reported in the wild.
Mitigation Recommendations
Upgrade ImageSharp to version 4.1.2 or later, where this vulnerability is fixed. If upgrading immediately is not possible, avoid setting DecoderOptions.ColorProfileHandling to Convert to prevent triggering the ICC conversion code path that leads to the out-of-bounds write.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-10-06T15:33:55.333Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac538122cdf04f656cddde7
Added to database: 10/06/2026, 18:04:02 UTC
Last enriched: 10/06/2026, 18:18:22 UTC
Last updated: 10/06/2026, 19:04:17 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.