CVE-2026-106111

MEDIUM Status: Received

CVSS Scores

CVSS v3.x Base Score
5.9
MEDIUM

Description

ImageSharp is a 2D graphics library. From 4.0.0 until 4.1.2, ExrBaseDecompressor.UndoZipCompression accepts a nonempty ZIP or ZIPS inflate result that is shorter than the EXR block's required size. ZipExrCompression.Decompress reconstructs the returned prefix while ExrDecoderCore processes the full expected block from a buffer obtained through Configuration.Default, allowing bytes retained from a completed prior ImageSharp operation to appear in decoded pixels. Applications that expose pixels or output from the later attacker-controlled EXR decode can disclose process-local image data. This issue is fixed in version 4.1.2.

Published
October 6, 2026 6:16 PM
Last Modified
October 6, 2026 7:17 PM
Source
[email protected]

Weaknesses (CWE)

CWE-226

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.