CVE-2026-106116: ImageSharp: BigTIFF IFD count can keep a decoder thread in a non-progressing loop
ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, ExifReader.ReadValues64 trusts the 64-bit BigTIFF IFD entry count and iterates once per declared entry. When fewer than 20 bytes remain, ExifReader.ReadValue64 returns without advancing the stream or terminating the outer loop, so a small malformed BigTIFF can keep one decoder thread executing for an attacker-controlled duration. This report does not claim worker-pool exhaustion. This issue is fixed in version 4.1.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ImageSharpto a version that resolves this vulnerability.Fixed in 4.1.2
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments using SixLabors ImageSharp versions from 2.0.0 through 4.1.1 are affected. Exposure requires the application to decode attacker-controlled BigTIFF images.
What does an attacker need to do to trigger the problem?
An attacker needs to supply a malformed BigTIFF whose declared 64-bit IFD entry count exceeds the available entry data. The decoder can then continue looping after fewer than 20 bytes remain, without advancing the stream.
What is the practical impact?
A small malformed image can keep a single decoder thread executing for an attacker-controlled duration. The report does not claim worker-pool exhaustion.
How can the issue be remediated?
Upgrade SixLabors ImageSharp to version 4.1.2, which fixes the issue.