PatchSiren cyber security CVE debrief
CVE-2026-106110 SixLabors CVE debrief
ImageSharp's TIFF CCITT Group 3 (T4) encoder can write beyond its allocated compressed-data buffer when encoding narrow 1-bit images. The unchecked writes can corrupt process memory and terminate the process. This issue affects SixLabors.ImageSharp (NuGet) from version 2.0.0 to 4.1.1. The vulnerability is triggered when the application encodes 1-bit image data with TiffCompression.CcittGroup3Fax. The affected path is reached when an application explicitly selects TiffEncoder.BitsPerPixel = Bit1 and TiffEncoder.Compression = CcittGroup3Fax. The vulnerability can also occur when an application decodes a TIFF and re-encodes it using the vulnerable T4 encoder.
- Vendor
- SixLabors
- Product
- SixLabors.ImageSharp
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for systems using ImageSharp for image processing, especially those handling TIFF images with CCITT Group 3 (T4) compression, should verify exposure and prioritize updating to a fixed version.
Why it matters
Defenders should care about CVE-2026-106110 because it affects ImageSharp's TIFF CCITT T4 encoder, potentially leading to process termination due to memory corruption. Systems using affected versions (2.0.0 to 4.1.1) and handling TIFF images with CCITT Group 3 (T4) compression are at risk. The impact is supported by the CVE record and source item details.
- Potential process termination due to memory corruption
- Need to verify exposure in systems using affected ImageSharp versions
- Priority on updating to version 4.1.2 or later
- Monitoring for potential crashes or memory corruption related to image processing
Technical summary
ImageSharp's TIFF CCITT Group 3 (T4) encoder can write beyond its allocated compressed-data buffer when encoding narrow 1-bit images. The unchecked writes can corrupt process memory and terminate the process. This issue affects SixLabors.ImageSharp (NuGet) from version 2.0.0 to 4.1.1. The vulnerability is triggered when encoding 1-bit image data with TiffCompression.CcittGroup3Fax. The affected path is reached when an application explicitly selects TiffEncoder.BitsPerPixel = Bit1 and TiffEncoder.Compression = CcittGroup3Fax.
Defensive priority
Defenders should prioritize verifying exposure in systems using ImageSharp for image processing, especially those handling TIFF images with CCITT Group 3 (T4) compression.
Recommended defensive actions
- Verify if systems using ImageSharp are exposed to this vulnerability by checking if they use the affected versions (2.0.0 to 4.1.1) and handle TIFF images with CCITT Group 3 (T4) compression.
- Update ImageSharp to version 4.1.2 or later to fix the vulnerability.
- Monitor systems for potential crashes or memory corruption related to image processing.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and source item provide details on the vulnerability in ImageSharp's TIFF CCITT T4 encoder. The affected package and versions are SixLabors.ImageSharp (NuGet) from 2.0.0 to 4.1.1. The vulnerability is triggered when encoding narrow 1-bit images with CCITT Group 3 (T4) compression. The source item and CVE record confirm the vulnerability and provide details on the affected versions and exploitation conditions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-106110 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-106110
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-106110 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106110
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
ImageSharp: TIFF CCITT T4 encoder can write past its compressed output buffer
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/NuGet/GHSA-j9gm-c75j-xc9q.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j9gm-c75j-xc9q
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/SixLabors/ImageSharp/pull/3187
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/SixLabors/ImageSharp
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.