PatchSiren cyber security CVE debrief
CVE-2026-106115 SixLabors CVE debrief
A vulnerability in the TIFF CCITT Group 4 (T6) encoder in SixLabors.ImageSharp can cause a process to terminate with an unhandled exception when encoding a 1-bit image. This issue affects versions 2.1.0 through 4.1.1 of the SixLabors.ImageSharp package. The vulnerability arises from the encoder writing beyond its logical compressed-data buffer. A valid 1×1 Group 4 TIFF decoded and re-encoded with the default TiffEncoder terminates the process with an unhandled exception. The T6 compressor was introduced by commit 3c9eb470a07a15012c2a29ad84090dcc804a7975, first released in v2.1.0, with the same Width * rowsPerStrip allocation and unchecked code writes.
- Vendor
- SixLabors
- Product
- SixLabors.ImageSharp
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for systems using SixLabors.ImageSharp should assess exposure and prioritize updating to version 4.1.2 or later. This includes reviewing affected versions, implementing compensating controls for exposed systems, and verifying the vulnerability in their environments. Security teams and operators should also review the official advisory and CVE record to understand the scope and severity of the vulnerability.
Why it matters
Defenders should care about this vulnerability as it can cause process termination and potential denial of service in systems using SixLabors.ImageSharp. Updating to version 4.1.2 or later is recommended.
- Potential process termination due to unhandled exceptions
- Possible denial of service due to image encoding issues
- Required verification of vulnerability in affected versions
- Need for updating to version 4.1.2 or later for fix
Technical summary
The TIFF CCITT Group 4 (T6) encoder in SixLabors.ImageSharp writes beyond its logical compressed-data buffer when encoding a 1-bit image. This can cause a process to terminate with an unhandled exception. The issue arises from a buffer allocation of Width * rowsPerStrip bytes, which for a 1×1 strip results in a single byte. After encoding the row, T6BitCompressor.CompressStrip writes beyond this buffer. The vulnerability was introduced in v2.1.0 and persists through v4.1.1. A fix is available in version 4.1.2 or later.
Defensive priority
Defenders should prioritize updating to version 4.1.2 or later of SixLabors.ImageSharp to address this vulnerability.
Recommended defensive actions
- Update to version 4.1.2 or later of SixLabors.ImageSharp
- Review and verify the vulnerability in affected versions
- Implement compensating controls to detect and prevent exploitation
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The vulnerability is caused by the TIFF CCITT T6 encoder writing beyond its logical compressed-data buffer when encoding a 1-bit image. A valid 1×1 Group 4 TIFF decoded and re-encoded with the default TiffEncoder terminates the process with an unhandled exception. Source history shows no capacity fix through v4.1.1. The T6 compressor was introduced by commit 3c9eb470a07a15012c2a29ad84090dcc804a7975, first released in v2.1.0.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-106115 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-106115
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-106115 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106115
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
ImageSharp: TIFF CCITT T6 encoder writes beyond an undersized output buffer
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/NuGet/GHSA-jjfr-hcj7-qf5w.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-jjfr-hcj7-qf5w
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/SixLabors/ImageSharp/pull/3187
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/SixLabors/ImageSharp/commit/a9498c6db3642ef92c712ebc81e706914ac16a95
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/SixLabors/ImageSharp
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.