PatchSiren cyber security CVE debrief
CVE-2026-106114 SixLabors CVE debrief
A vulnerability in ImageSharp's ICC CLUT parsing allows for memory allocation from attacker-controlled dimensions before verifying CLUT values. This affects SixLabors.ImageSharp NuGet package versions >= 1.0.0-beta0001 and <= 4.1.1. The issue is fixed in version 4.1.2. ImageSharp's ICC CLUT parsing vulnerability allows memory allocation from unvalidated dimensions, posing a risk of denial of service through potential memory exhaustion. Defenders should prioritize updating to version 4.1.2 or later and review image processing workflows for exposure.
- Vendor
- SixLabors
- Product
- SixLabors.ImageSharp
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for image processing and conversion workflows using ImageSharp, NuGet package managers, and developers using SixLabors.ImageSharp should assess exposure and prioritize updates.
Why it matters
CVE-2026-106114 is a vulnerability in ImageSharp's ICC CLUT parsing that allows for memory allocation from attacker-controlled dimensions. Defenders should prioritize updating to version 4.1.2 or later and review image processing workflows for exposure.
- Potential for denial of service through memory allocation
- Need for verification of affected versions and exposure
- Priority for updating to fixed version 4.1.2 or later
- Importance of reviewing image processing workflows for vulnerability
Technical summary
The vulnerability in ImageSharp's ICC CLUT parsing allows for memory allocation from attacker-controlled dimensions before verifying CLUT values. This affects SixLabors.ImageSharp NuGet package versions >= 1.0.0-beta0001 and <= 4.1.1. The issue is fixed in version 4.1.2. ImageSharp's ICC CLUT parsing vulnerability allows memory allocation from unvalidated dimensions, posing a risk of denial of service through potential memory exhaustion. The vulnerability is confirmed in versions 1.0.0-beta0001 through 4.1.1 of the SixLabors.ImageSharp NuGet package.
Defensive priority
Defenders should prioritize updating to version 4.1.2 or later to mitigate this vulnerability. Image processing and conversion workflows using ImageSharp should be reviewed for exposure.
Recommended defensive actions
- Update to SixLabors.ImageSharp version 4.1.2 or later
- Review and inventory ImageSharp usage in NuGet packages
- Assess exposure in image processing and conversion workflows
- Verify affected versions and exposure in image processing workflows
- Prioritize updating to fixed version 4.1.2 or later
- Review compensating controls for exposed systems while remediation is scheduled
- Track exceptions and retest remediated assets
Evidence notes
The vulnerability is confirmed in versions 1.0.0-beta0001 through 4.1.1 of the SixLabors.ImageSharp NuGet package. The issue involves allocating memory based on unvalidated CLUT channel and grid dimensions from a malformed ICC profile.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-106114 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-106114
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-106114 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106114
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
ImageSharp: ICC CLUT parsing allocates from unvalidated channel and grid dimensions
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/NuGet/GHSA-gwg2-r3hj-4w44.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-gwg2-r3hj-4w44
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/SixLabors/ImageSharp/pull/3187
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/SixLabors/ImageSharp/commit/8de892a7623aa8a09ba2333b624c8d2eb98325df
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/SixLabors/ImageSharp
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.