CVE-2026-106111: Sixlabors Imagesharp

Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.

ImageSharp is a 2D graphics library. From 4.0.0 until 4.1.2, ExrBaseDecompressor.UndoZipCompression accepts a nonempty ZIP or ZIPS inflate result that is shorter than the EXR block's required size. ZipExrCompression.Decompress reconstructs the returned prefix while ExrDecoderCore processes the full expected block from a buffer obtained through Configuration.Default, allowing bytes retained from a completed prior ImageSharp operation to appear in decoded pixels. Applications that expose pixels or output from the later attacker-controlled EXR decode can disclose process-local image data. This issue is fixed in version 4.1.2.

Affected products

  • Sixlabors Imagesharp: from 4.0.0, before 4.1.2 (fixed in 4.1.2)

Published 2026-10-06. Last modified 2026-10-06.