PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-106115 SixLabors CVE debrief

A vulnerability in the TIFF CCITT Group 4 (T6) encoder in SixLabors.ImageSharp can cause a process to terminate with an unhandled exception when encoding a 1-bit image. This issue affects versions 2.1.0 through 4.1.1 of the SixLabors.ImageSharp package. The vulnerability arises from the encoder writing beyond its logical compressed-data buffer. A valid 1×1 Group 4 TIFF decoded and re-encoded with the default TiffEncoder terminates the process with an unhandled exception. The T6 compressor was introduced by commit 3c9eb470a07a15012c2a29ad84090dcc804a7975, first released in v2.1.0, with the same Width * rowsPerStrip allocation and unchecked code writes.

Vendor
SixLabors
Product
SixLabors.ImageSharp
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for systems using SixLabors.ImageSharp should assess exposure and prioritize updating to version 4.1.2 or later. This includes reviewing affected versions, implementing compensating controls for exposed systems, and verifying the vulnerability in their environments. Security teams and operators should also review the official advisory and CVE record to understand the scope and severity of the vulnerability.

Why it matters

Defenders should care about this vulnerability as it can cause process termination and potential denial of service in systems using SixLabors.ImageSharp. Updating to version 4.1.2 or later is recommended.

  • Potential process termination due to unhandled exceptions
  • Possible denial of service due to image encoding issues
  • Required verification of vulnerability in affected versions
  • Need for updating to version 4.1.2 or later for fix

Technical summary

The TIFF CCITT Group 4 (T6) encoder in SixLabors.ImageSharp writes beyond its logical compressed-data buffer when encoding a 1-bit image. This can cause a process to terminate with an unhandled exception. The issue arises from a buffer allocation of Width * rowsPerStrip bytes, which for a 1×1 strip results in a single byte. After encoding the row, T6BitCompressor.CompressStrip writes beyond this buffer. The vulnerability was introduced in v2.1.0 and persists through v4.1.1. A fix is available in version 4.1.2 or later.

Defensive priority

Defenders should prioritize updating to version 4.1.2 or later of SixLabors.ImageSharp to address this vulnerability.

Recommended defensive actions

  • Update to version 4.1.2 or later of SixLabors.ImageSharp
  • Review and verify the vulnerability in affected versions
  • Implement compensating controls to detect and prevent exploitation
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The vulnerability is caused by the TIFF CCITT T6 encoder writing beyond its logical compressed-data buffer when encoding a 1-bit image. A valid 1×1 Group 4 TIFF decoded and re-encoded with the default TiffEncoder terminates the process with an unhandled exception. Source history shows no capacity fix through v4.1.1. The T6 compressor was introduced by commit 3c9eb470a07a15012c2a29ad84090dcc804a7975, first released in v2.1.0.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-106115 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-106115

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-106115 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106115

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • ImageSharp: TIFF CCITT T6 encoder writes beyond an undersized output buffer

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/NuGet/GHSA-jjfr-hcj7-qf5w.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-jjfr-hcj7-qf5w

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/SixLabors/ImageSharp/pull/3187

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/SixLabors/ImageSharp

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.