Out-of-bounds Write Affecting sixlabors.imagesharp package, versions [3.0.0,4.1.1)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.43% (35th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DOTNET-SIXLABORSIMAGESHARP-20562166
  • published7 Oct 2026
  • disclosed6 Oct 2026
  • creditKimiSecurityTeam

Introduced: 6 Oct 2026

NewCVE-2026-106117  (opens in a new tab)
CWE-787  (opens in a new tab)

How to fix?

Upgrade SixLabors.ImageSharp to version 4.1.1 or higher.

Overview

Affected versions of this package are vulnerable to Out-of-bounds Write in the CCITT fax decompression paths T4TiffCompression.Decompress() and ModifiedHuffmanTiffCompression.Decompress(), which hand a decoded run length to the unchecked bit writers in BitWriterUtils.cs without first confirming it fits the remaining row, the Modified Huffman path checking only after the write has happened. An attacker can write past the end of the strip buffer at an offset and length they control, crashing the process in a way application error handling does not intercept and exposing the heap to corruption, by supplying a TIFF using Compression=3 for Group 3 1D or Compression=2 for Modified Huffman whose runs decode to more pixels than the image width. This requires the application to decode untrusted TIFF input through Image.Load, is confined to strip based storage with those two compressions, and needs no non default configuration.

CVSS Base Scores

version 4.0
version 3.1