SixLabors.ImageSharp
NuGet14 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting SixLabors.ImageSharppage 1 of 1
- CVE-2024-27929HIGHCVSS 7.1EG 7.1fixed in 3.1.3 or 2.1.7, by version range2024-03-05
vulnerable: 1.0.0 ... 2.1.6 (23 versions)
ImageSharp is a managed, cross-platform, 2D graphics library. A heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when an attacker passes a specially cr…
- CVE-2024-32035MEDIUMCVSS 5.3EG 5.3fixed in 2.1.8 or 3.1.4, by version range2024-04-15
vulnerable: 3.0.0 ... 3.1.3 (7 versions)
ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in image decoders. The vulnerability is triggered when ImageSharp att…
- CVE-2024-32036MEDIUMCVSS 5.3EG 5.3fixed in 2.1.8 or 3.1.4, by version range2024-04-15
vulnerable: 3.0.0 ... 3.1.3 (7 versions)
ImageSharp is a 2D graphics API. A data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potent…
- CVE-2024-41131HIGHCVSS 7.5EG 7.5fixed in 2.1.9 or 3.1.5, by version range2024-07-22
vulnerable: 3.0.0 ... 3.1.4 (8 versions)
ImageSharp is a 2D graphics API. An Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. All user…
- CVE-2024-41132MEDIUMCVSS 5.3EG 5.3fixed in 2.1.9 or 3.1.5, by version range2024-07-22
vulnerable: 3.0.0 ... 3.1.4 (8 versions)
ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp at…
- CVE-2025-27598HIGHCVSS 7.5EG 7.5fixed in 3.1.7 or 2.1.10, by version range2025-03-06
vulnerable: 1.0.0 ... 2.1.9 (26 versions)
ImageSharp is a 2D graphics API. An Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. The prob…
- CVE-2025-54575MEDIUMCVSS 5.3EG 5.3fixed in 2.1.11 or 3.1.11, by version range2025-07-30
vulnerable: 3.0.0 ... 3.1.9 (14 versions)
ImageSharp is a 2D graphics library. In versions below 2.1.11 and 3.0.0 through 3.1.10, a specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to e…
- CVE-2026-106110HIGHCVSS 7.5EG 7.5fixed in 4.1.22026-10-06
vulnerable: 2.0.0 ... 4.1.1 (34 versions)
ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Group 3 encoder allocates an undersized compressed-data buffer for narrow 1-bit images. TiffCcittCompressor.Initialize does not reserve enough space for the row da…
- CVE-2026-106111MEDIUMCVSS 5.9EG 5.9fixed in 4.1.22026-10-06
vulnerable: 4.0.0, 4.1.0, 4.1.1
ImageSharp is a 2D graphics library. From 4.0.0 until 4.1.2, ExrBaseDecompressor.UndoZipCompression accepts a nonempty ZIP or ZIPS inflate result that is shorter than the EXR block's required size. ZipExrCompression.Decompress reconstructs…
- CVE-2026-106112HIGHCVSS 7.5EG 7.5fixed in 4.1.22026-10-06
vulnerable: 4.0.0, 4.1.0, 4.1.1
ImageSharp is a 2D graphics library. From 4.0.0 until 4.1.2, ICC LUT16 conversion accepts more than four output channels even though ClutCalculator.Calculate and LutEntryCalculator.CalculateLut store intermediate and output values in Vecto…
- CVE-2026-106113HIGHCVSS 7.5EG 7.5fixed in 4.1.22026-10-06
vulnerable: 2.0.0 ... 4.1.1 (34 versions)
ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, decoding an attacker-supplied 32-bit floating-point TIFF as Image<HalfVector4> and applying HistogramEqualization can produce a non-finite or out-of-range luminance in ColorNumer…
- CVE-2026-106114MEDIUMCVSS 5.3EG 5.3fixed in 4.1.22026-10-06
vulnerable: 1.0.0 ... 4.1.1 (49 versions)
ImageSharp is a 2D graphics library. From 1.0.0-beta0001 until 4.1.2, ICC CLUT parsing calculates allocation sizes from attacker-declared channel and grid dimensions before confirming that the profile contains the declared values. IccDataR…
- CVE-2026-106115HIGHCVSS 7.5EG 7.5fixed in 4.1.22026-10-06
vulnerable: 2.1.0 ... 4.1.1 (33 versions)
ImageSharp is a 2D graphics library. From 2.1.0 until 4.1.2, the TIFF CCITT Group 4 encoder allocates Width times rowsPerStrip bytes even though T6BitCompressor.CompressStrip can emit encoded row data and two 12-bit end-of-facsimile-block …
- CVE-2026-106116MEDIUMCVSS 5.3EG 5.3fixed in 4.1.22026-10-06
vulnerable: 2.0.0 ... 4.1.1 (34 versions)
ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, ExifReader.ReadValues64 trusts the 64-bit BigTIFF IFD entry count and iterates once per declared entry. When fewer than 20 bytes remain, ExifReader.ReadValue64 returns without ad…
Check whether SixLabors.ImageSharp is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for SixLabors.ImageSharp CVEs against the assets you own.
Book a Demo →