ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, ExifReader.ReadValues64 trusts the 64-bit BigTIFF IFD entry count and iterates once per declared entry. When fewer than 20 bytes remain, ExifReader.ReadValue64 returns without advancing the stream or terminating the outer loop, so a small malformed BigTIFF can keep one decoder thread executing for an attacker-controlled duration. This report does not claim worker-pool exhaustion. This issue is fixed in version 4.1.2.

Project Subscriptions

Vendors Products
Sixlabors Subscribe
Imagesharp Subscribe
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-wmxv-xphr-5c9g ImageSharp: BigTIFF IFD count can keep a decoder thread in a non-progressing loop
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 07 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Sixlabors
Sixlabors imagesharp
Vendors & Products Sixlabors
Sixlabors imagesharp

Tue, 06 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Description ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, ExifReader.ReadValues64 trusts the 64-bit BigTIFF IFD entry count and iterates once per declared entry. When fewer than 20 bytes remain, ExifReader.ReadValue64 returns without advancing the stream or terminating the outer loop, so a small malformed BigTIFF can keep one decoder thread executing for an attacker-controlled duration. This report does not claim worker-pool exhaustion. This issue is fixed in version 4.1.2.
Title ImageSharp: BigTIFF IFD count can keep a decoder thread in a non-progressing loop
Weaknesses CWE-835
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T18:21:55.088Z

Reserved: 2026-10-06T15:33:55.333Z

Link: CVE-2026-106116

cve-icon Vulnrichment

Updated: 2026-10-06T18:21:10.476Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T18:16:53.400

Modified: 2026-10-06T20:03:40.690

Link: CVE-2026-106116

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T06:00:08Z

Weaknesses