PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-106111 SixLabors CVE debrief

A crafted ZIP-compressed OpenEXR image can return stale memory from a prior ImageSharp operation as decoded pixels. This process-local, cross-operation information-disclosure defect is relevant when an application uses the shared `Configuration.Default` allocator for separate image operations and exposes pixels or output derived from a later attacker-controlled EXR decode.

Vendor
SixLabors
Product
SixLabors.ImageSharp
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders of applications using ImageSharp for image processing, especially those exposing decoded image data or using shared allocators, should assess their exposure and prioritize verification and remediation.

Why it matters

CVE-2026-106111 is an information disclosure vulnerability in ImageSharp's EXR ZIP decoder. Defenders should verify and remediate to prevent potential exposure of sensitive data.

  • Potential information disclosure through exposure of stale memory
  • Verification of application usage of shared allocators is necessary
  • Remediation requires upgrading to ImageSharp version 4.1.2 or later
  • Assessment of decoded image data exposure is crucial

Technical summary

The ZIP decoder in ImageSharp accepts a non-empty inflate result shorter than the EXR block's required size, leading to exposure of stale memory from prior operations. This process-local, cross-operation information-disclosure defect is relevant when an application uses the shared `Configuration.Default` allocator for separate image operations and exposes pixels or output derived from a later attacker-controlled EXR decode. Defenders should prioritize verifying and upgrading to ImageSharp version 4.1.2 or later, reviewing application usage of shared allocators, and assessing exposure of decoded image data.

Defensive priority

Defenders should prioritize verifying and upgrading to ImageSharp version 4.1.2 or later, reviewing application usage of shared allocators, and assessing exposure of decoded image data.

Recommended defensive actions

  • Verify and upgrade to ImageSharp version 4.1.2 or later
  • Review application usage of shared allocators for separate image operations
  • Assess exposure of decoded image data
  • Monitor for potential information disclosure
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The source corpus provides details on the affected ImageSharp versions (4.0.0, 4.1.0, 4.1.1) and the fixed version (4.1.2). The defect is in the ZIP decoder accepting a non-empty inflate result shorter than the EXR block's required size.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-106111 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-106111

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-106111 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106111

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • ImageSharp: EXR ZIP decoder can expose stale allocator data after a short inflate

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/NuGet/GHSA-4q3p-rj5x-xv7p.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-4q3p-rj5x-xv7p

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/SixLabors/ImageSharp/pull/3187

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/SixLabors/ImageSharp/commit/3c43cf583fdd98eff0f451397affaa31c6a2e6b1

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/SixLabors/ImageSharp/commit/6ed2a275217d39301e76df42acec2a9533b39d2b

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/SixLabors/ImageSharp

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.