PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-106110 SixLabors CVE debrief

ImageSharp's TIFF CCITT Group 3 (T4) encoder can write beyond its allocated compressed-data buffer when encoding narrow 1-bit images. The unchecked writes can corrupt process memory and terminate the process. This issue affects SixLabors.ImageSharp (NuGet) from version 2.0.0 to 4.1.1. The vulnerability is triggered when the application encodes 1-bit image data with TiffCompression.CcittGroup3Fax. The affected path is reached when an application explicitly selects TiffEncoder.BitsPerPixel = Bit1 and TiffEncoder.Compression = CcittGroup3Fax. The vulnerability can also occur when an application decodes a TIFF and re-encodes it using the vulnerable T4 encoder.

Vendor
SixLabors
Product
SixLabors.ImageSharp
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for systems using ImageSharp for image processing, especially those handling TIFF images with CCITT Group 3 (T4) compression, should verify exposure and prioritize updating to a fixed version.

Why it matters

Defenders should care about CVE-2026-106110 because it affects ImageSharp's TIFF CCITT T4 encoder, potentially leading to process termination due to memory corruption. Systems using affected versions (2.0.0 to 4.1.1) and handling TIFF images with CCITT Group 3 (T4) compression are at risk. The impact is supported by the CVE record and source item details.

  • Potential process termination due to memory corruption
  • Need to verify exposure in systems using affected ImageSharp versions
  • Priority on updating to version 4.1.2 or later
  • Monitoring for potential crashes or memory corruption related to image processing

Technical summary

ImageSharp's TIFF CCITT Group 3 (T4) encoder can write beyond its allocated compressed-data buffer when encoding narrow 1-bit images. The unchecked writes can corrupt process memory and terminate the process. This issue affects SixLabors.ImageSharp (NuGet) from version 2.0.0 to 4.1.1. The vulnerability is triggered when encoding 1-bit image data with TiffCompression.CcittGroup3Fax. The affected path is reached when an application explicitly selects TiffEncoder.BitsPerPixel = Bit1 and TiffEncoder.Compression = CcittGroup3Fax.

Defensive priority

Defenders should prioritize verifying exposure in systems using ImageSharp for image processing, especially those handling TIFF images with CCITT Group 3 (T4) compression.

Recommended defensive actions

  • Verify if systems using ImageSharp are exposed to this vulnerability by checking if they use the affected versions (2.0.0 to 4.1.1) and handle TIFF images with CCITT Group 3 (T4) compression.
  • Update ImageSharp to version 4.1.2 or later to fix the vulnerability.
  • Monitor systems for potential crashes or memory corruption related to image processing.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and source item provide details on the vulnerability in ImageSharp's TIFF CCITT T4 encoder. The affected package and versions are SixLabors.ImageSharp (NuGet) from 2.0.0 to 4.1.1. The vulnerability is triggered when encoding narrow 1-bit images with CCITT Group 3 (T4) compression. The source item and CVE record confirm the vulnerability and provide details on the affected versions and exploitation conditions.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-106110 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-106110

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-106110 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106110

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • ImageSharp: TIFF CCITT T4 encoder can write past its compressed output buffer

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/NuGet/GHSA-j9gm-c75j-xc9q.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j9gm-c75j-xc9q

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/SixLabors/ImageSharp/pull/3187

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/SixLabors/ImageSharp

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.