PatchSiren cyber security CVE debrief
CVE-2026-106112 SixLabors CVE debrief
A memory corruption vulnerability exists in ImageSharp when ICC conversion is enabled and a malformed embedded ICC LUT16 profile with more than four output channels is processed. The ICC parser accepts up to 15 CLUT output channels, while the conversion implementation stores intermediate values in `Vector4`. Affected versions include 4.0.0, 4.1.0, and 4.1.1 of the `SixLabors.ImageSharp` NuGet package.
- Vendor
- SixLabors
- Product
- SixLabors.ImageSharp
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for systems using ImageSharp for ICC conversion should assess exposure and verify the integrity of color profiles. This includes operators, platform administrators, vulnerability management teams, and security teams who need to prioritize verifying exposure in systems using ImageSharp for ICC conversion and assessing the integrity of color profiles due to a memory corruption vulnerability.
Why it matters
Defenders should prioritize verifying exposure in systems using ImageSharp for ICC conversion and assessing the integrity of color profiles due to a memory corruption vulnerability.
- Potential memory corruption during ICC conversion
- Verification of color profile integrity is necessary
- Upgrade to version 4.1.2 or later to address the vulnerability
Technical summary
The ICC parser in ImageSharp accepts up to 15 CLUT output channels, but the conversion implementation stores intermediate values in `Vector4`, which can lead to memory corruption when processing malformed ICC LUT16 profiles. Affected versions include 4.0.0, 4.1.0, and 4.1.1 of the `SixLabors.ImageSharp` NuGet package. This vulnerability can be triggered by a malformed embedded ICC LUT16 profile with more than four output channels, potentially causing memory corruption during ICC conversion in ImageSharp. Defenders should prioritize verifying exposure in systems using ImageSharp for ICC conversion and assessing the integrity of color profiles.
Defensive priority
Defenders should prioritize verifying exposure in systems using ImageSharp for ICC conversion and assessing the integrity of color profiles.
Recommended defensive actions
- Verify the version of SixLabors.ImageSharp in use and upgrade to 4.1.2 or later if necessary.
- Assess the integrity of color profiles used in ImageSharp ICC conversion.
- Monitor systems using ImageSharp for ICC conversion for potential memory corruption.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The vulnerability was reproduced in the `ColorProfileHandling.Convert` path with an attacker-controlled profile declaring three input channels and fifteen output channels. This issue arises from the ICC parser accepting up to 15 CLUT output channels, while the conversion implementation stores intermediate values in `Vector4`, potentially leading to memory corruption. Defenders should verify the integrity of color profiles used in ImageSharp ICC conversion and assess exposure in systems using ImageSharp for ICC conversion.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-106112 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-106112
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-106112 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106112
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
ImageSharp: ICC LUT16 output channel count can write beyond Vector4
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/NuGet/GHSA-ffp7-56pq-64mr.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-ffp7-56pq-64mr
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/SixLabors/ImageSharp/pull/3187
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/SixLabors/ImageSharp/commit/b03f0ed7e5be760eecc740fa53dd166b18ae9b23
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/SixLabors/ImageSharp
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.