PatchSiren cyber security CVE debrief
CVE-2026-106111 SixLabors CVE debrief
A crafted ZIP-compressed OpenEXR image can return stale memory from a prior ImageSharp operation as decoded pixels. This process-local, cross-operation information-disclosure defect is relevant when an application uses the shared `Configuration.Default` allocator for separate image operations and exposes pixels or output derived from a later attacker-controlled EXR decode.
- Vendor
- SixLabors
- Product
- SixLabors.ImageSharp
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders of applications using ImageSharp for image processing, especially those exposing decoded image data or using shared allocators, should assess their exposure and prioritize verification and remediation.
Why it matters
CVE-2026-106111 is an information disclosure vulnerability in ImageSharp's EXR ZIP decoder. Defenders should verify and remediate to prevent potential exposure of sensitive data.
- Potential information disclosure through exposure of stale memory
- Verification of application usage of shared allocators is necessary
- Remediation requires upgrading to ImageSharp version 4.1.2 or later
- Assessment of decoded image data exposure is crucial
Technical summary
The ZIP decoder in ImageSharp accepts a non-empty inflate result shorter than the EXR block's required size, leading to exposure of stale memory from prior operations. This process-local, cross-operation information-disclosure defect is relevant when an application uses the shared `Configuration.Default` allocator for separate image operations and exposes pixels or output derived from a later attacker-controlled EXR decode. Defenders should prioritize verifying and upgrading to ImageSharp version 4.1.2 or later, reviewing application usage of shared allocators, and assessing exposure of decoded image data.
Defensive priority
Defenders should prioritize verifying and upgrading to ImageSharp version 4.1.2 or later, reviewing application usage of shared allocators, and assessing exposure of decoded image data.
Recommended defensive actions
- Verify and upgrade to ImageSharp version 4.1.2 or later
- Review application usage of shared allocators for separate image operations
- Assess exposure of decoded image data
- Monitor for potential information disclosure
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The source corpus provides details on the affected ImageSharp versions (4.0.0, 4.1.0, 4.1.1) and the fixed version (4.1.2). The defect is in the ZIP decoder accepting a non-empty inflate result shorter than the EXR block's required size.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-106111 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-106111
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-106111 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106111
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
ImageSharp: EXR ZIP decoder can expose stale allocator data after a short inflate
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/NuGet/GHSA-4q3p-rj5x-xv7p.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-4q3p-rj5x-xv7p
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/SixLabors/ImageSharp/pull/3187
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/SixLabors/ImageSharp/commit/3c43cf583fdd98eff0f451397affaa31c6a2e6b1
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/SixLabors/ImageSharp/commit/6ed2a275217d39301e76df42acec2a9533b39d2b
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/SixLabors/ImageSharp
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.