PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-106114 SixLabors CVE debrief

A vulnerability in ImageSharp's ICC CLUT parsing allows for memory allocation from attacker-controlled dimensions before verifying CLUT values. This affects SixLabors.ImageSharp NuGet package versions >= 1.0.0-beta0001 and <= 4.1.1. The issue is fixed in version 4.1.2. ImageSharp's ICC CLUT parsing vulnerability allows memory allocation from unvalidated dimensions, posing a risk of denial of service through potential memory exhaustion. Defenders should prioritize updating to version 4.1.2 or later and review image processing workflows for exposure.

Vendor
SixLabors
Product
SixLabors.ImageSharp
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for image processing and conversion workflows using ImageSharp, NuGet package managers, and developers using SixLabors.ImageSharp should assess exposure and prioritize updates.

Why it matters

CVE-2026-106114 is a vulnerability in ImageSharp's ICC CLUT parsing that allows for memory allocation from attacker-controlled dimensions. Defenders should prioritize updating to version 4.1.2 or later and review image processing workflows for exposure.

  • Potential for denial of service through memory allocation
  • Need for verification of affected versions and exposure
  • Priority for updating to fixed version 4.1.2 or later
  • Importance of reviewing image processing workflows for vulnerability

Technical summary

The vulnerability in ImageSharp's ICC CLUT parsing allows for memory allocation from attacker-controlled dimensions before verifying CLUT values. This affects SixLabors.ImageSharp NuGet package versions >= 1.0.0-beta0001 and <= 4.1.1. The issue is fixed in version 4.1.2. ImageSharp's ICC CLUT parsing vulnerability allows memory allocation from unvalidated dimensions, posing a risk of denial of service through potential memory exhaustion. The vulnerability is confirmed in versions 1.0.0-beta0001 through 4.1.1 of the SixLabors.ImageSharp NuGet package.

Defensive priority

Defenders should prioritize updating to version 4.1.2 or later to mitigate this vulnerability. Image processing and conversion workflows using ImageSharp should be reviewed for exposure.

Recommended defensive actions

  • Update to SixLabors.ImageSharp version 4.1.2 or later
  • Review and inventory ImageSharp usage in NuGet packages
  • Assess exposure in image processing and conversion workflows
  • Verify affected versions and exposure in image processing workflows
  • Prioritize updating to fixed version 4.1.2 or later
  • Review compensating controls for exposed systems while remediation is scheduled
  • Track exceptions and retest remediated assets

Evidence notes

The vulnerability is confirmed in versions 1.0.0-beta0001 through 4.1.1 of the SixLabors.ImageSharp NuGet package. The issue involves allocating memory based on unvalidated CLUT channel and grid dimensions from a malformed ICC profile.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-106114 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-106114

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-106114 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106114

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • ImageSharp: ICC CLUT parsing allocates from unvalidated channel and grid dimensions

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/NuGet/GHSA-gwg2-r3hj-4w44.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-gwg2-r3hj-4w44

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/SixLabors/ImageSharp/pull/3187

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/SixLabors/ImageSharp/commit/8de892a7623aa8a09ba2333b624c8d2eb98325df

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/SixLabors/ImageSharp

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.