CVE-2025-27598: Sixlabors Imagesharp

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

ImageSharp is a 2D graphics API. An Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. The problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10.

Affected products

  • Sixlabors Imagesharp: before 2.1.10 (fixed in 2.1.10); from 3.0.0, before 3.1.7 (fixed in 3.1.7)

Published 2025-03-06. Last modified 2026-06-17.