5.3
CVE-2026-106116
- EPSS 0.37%
- Veröffentlicht 06.10.2026 17:51:36
- Zuletzt bearbeitet 06.10.2026 20:03:40
- Erkennungen
ImageSharp: BigTIFF IFD count can keep a decoder thread in a non-progressing loop
ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, ExifReader.ReadValues64 trusts the 64-bit BigTIFF IFD entry count and iterates once per declared entry. When fewer than 20 bytes remain, ExifReader.ReadValue64 returns without advancing the stream or terminating the outer loop, so a small malformed BigTIFF can keep one decoder thread executing for an attacker-controlled duration. This report does not claim worker-pool exhaustion. This issue is fixed in version 4.1.2.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSixLabors
≫
Produkt
ImageSharp
Version
>= 2.0.0, < 4.1.2
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.37% | 0.283 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
|
CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
https://github.com/SixLabors/ImageSharp/pull/3187
https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2
https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-wmxv-xphr-5c9g
https://github.com/SixLabors/ImageSharp/commit/92b12d72550ebb6be5b1e22e559c361fd863a6ec