{"id":"CVE-2026-106113","title":"ImageSharp is a 2D graphics library","summary":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, decoding an attacker-supplied 32-bit floating-point TIFF as Image<HalfVector4> and applying HistogramEqualization can produce a non-finite or out-of-range luminance in ColorNum…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-787"],"vendor":"SixLabors","product":"ImageSharp","affected":["ImageSharp >= 2.0.0, < 4.1.2"],"published":"2026-10-06","updated":"2026-10-07","sourceUpdated":"2026-10-07T17:16:47.540","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-106113","references":[{"url":"https://github.com/SixLabors/ImageSharp/commit/c4c4bf292298c026df470db1a17ff826515fd95d","label":"security-advisories@github.com"},{"url":"https://github.com/SixLabors/ImageSharp/pull/3187","label":"security-advisories@github.com"},{"url":"https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","label":"security-advisories@github.com"},{"url":"https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-j3p4-wp97-rph4","label":"security-advisories@github.com"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106113"},{"url":"https://github.com/advisories/GHSA-j3p4-wp97-rph4"}],"tags":["nvd","cve.org","ghsa","nuget"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-10-07T15:39:17.492179Z"},"epss":0.0035,"epssPercentile":0.26575,"ingestedAt":"2026-10-06T18:11:36.229Z","aliases":["GHSA-j3p4-wp97-rph4"],"ecosystem":"nuget","patched":["SixLabors.ImageSharp 4.1.2"],"slug":"CVE-2026-106113","body":"## Overview\n\nImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, decoding an attacker-supplied 32-bit floating-point TIFF as Image<HalfVector4> and applying HistogramEqualization can produce a non-finite or out-of-range luminance in ColorNumerics.GetBT709Luminance. GrayscaleLevelsRowOperation.Invoke uses the resulting value as an unchecked histogram offset, causing an unsafe out-of-range access and process termination. Adaptive Histogram Equalization and AutoLevel are not affected by this report. This issue is fixed in version 4.1.2.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-106113)\n\nAffected packages:\n\n- `SixLabors.ImageSharp >= 2.0.0, <= 4.1.1`\n\nPatched in:\n\n- `SixLabors.ImageSharp 4.1.2`\n\nSource: https://github.com/advisories/GHSA-j3p4-wp97-rph4","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}