CVE-2026-106113: ImageSharp: HistogramEqualization uses an unvalidated luminance as an unchecked histogram index
ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, decoding an attacker-supplied 32-bit floating-point TIFF as Image<HalfVector4> and applying HistogramEqualization can produce a non-finite or out-of-range luminance in ColorNumerics.GetBT709Luminance. GrayscaleLevelsRowOperation.Invoke uses the resulting value as an unchecked histogram offset, causing an unsafe out-of-range access and process termination. Adaptive Histogram Equalization and AutoLevel are not affected by this report. This issue is fixed in version 4.1.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ImageSharpto a version that resolves this vulnerability.Fixed in 4.1.2
Event History
Frequently Asked Questions
Which applications are exposed to this issue?
Applications using ImageSharp versions 2.0.0 through 4.1.2 are exposed if they decode attacker-controlled 32-bit floating-point TIFF files as Image<HalfVector4> and apply HistogramEqualization. The impact is process termination.
What input and processing conditions are required for exploitation?
An attacker needs to provide a 32-bit floating-point TIFF that produces a non-finite or out-of-range luminance value. The application must then run HistogramEqualization on the decoded Image<HalfVector4> image.
Are related ImageSharp image-adjustment operations affected?
No. Adaptive Histogram Equalization and AutoLevel are not affected by this report.
What remediation is available?
Update ImageSharp to version 4.1.2, which fixes the issue. If updating cannot happen immediately, avoid applying HistogramEqualization to attacker-supplied 32-bit floating-point TIFF images decoded as Image<HalfVector4>.