VulnSea

SixLabors has 9 CVEs on record. Disclosure cadence is accelerating: 9 in the last 90 days against 0 in the 90 before. The busiest recent month was October 2026 with 9. The median CVSS is 7.5 (high). None have a confirmed exploitation report. The most common weakness class is CWE-787 (6).

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
—
Last 90 days
9 prev 0

Products

  • ImageSharp 9
9
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

SixLabors vulnerabilities

CVEs affecting SixLabors, newest first. Open any entry for full detail, references, and exploit status.

9 CVEsRSS

CVE-2026-106118High· 7.5
yesterday

ImageSharp is a 2D graphics library

ImageSharp is a 2D graphics library. From 3.0.0 until 4.1.1, tiled TIFF decoding allocates a destination buffer using TileWidth but TiffDecompressorsFactory.Create constructs T4, T6, and Modified Huffman decompressors using the full fram…

▾ TwilightSixLabors · ImageSharpvia NVD
CVE-2026-106110High· 7.5
yesterday

ImageSharp is a 2D graphics library

ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Group 3 encoder allocates an undersized compressed-data buffer for narrow 1-bit images. TiffCcittCompressor.Initialize does not reserve enough space for the row …

▾ TwilightSixLabors · ImageSharpvia NVD
CVE-2026-106114Medium· 5.3PoC
yesterday

ImageSharp is a 2D graphics library

ImageSharp is a 2D graphics library. From 1.0.0-beta0001 until 4.1.2, ICC CLUT parsing calculates allocation sizes from attacker-declared channel and grid dimensions before confirming that the profile contains the declared values. IccDat…

▾ TwilightSixLabors · ImageSharpvia NVD
CVE-2026-106113High· 7.5
yesterday

ImageSharp is a 2D graphics library

ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, decoding an attacker-supplied 32-bit floating-point TIFF as Image<HalfVector4> and applying HistogramEqualization can produce a non-finite or out-of-range luminance in ColorNum…

▾ TwilightSixLabors · ImageSharpvia NVD
CVE-2026-106111Medium· 5.9PoC
yesterday

ImageSharp is a 2D graphics library

ImageSharp is a 2D graphics library. From 4.0.0 until 4.1.2, ExrBaseDecompressor.UndoZipCompression accepts a nonempty ZIP or ZIPS inflate result that is shorter than the EXR block's required size. ZipExrCompression.Decompress reconstruc…

▾ TwilightSixLabors · ImageSharpvia NVD
CVE-2026-106112High· 7.5
yesterday

ImageSharp is a 2D graphics library

ImageSharp is a 2D graphics library. From 4.0.0 until 4.1.2, ICC LUT16 conversion accepts more than four output channels even though ClutCalculator.Calculate and LutEntryCalculator.CalculateLut store intermediate and output values in Vec…

▾ TwilightSixLabors · ImageSharpvia NVD
CVE-2026-106115High· 7.5
yesterday

ImageSharp is a 2D graphics library

ImageSharp is a 2D graphics library. From 2.1.0 until 4.1.2, the TIFF CCITT Group 4 encoder allocates Width times rowsPerStrip bytes even though T6BitCompressor.CompressStrip can emit encoded row data and two 12-bit end-of-facsimile-bloc…

▾ TwilightSixLabors · ImageSharpvia NVD
CVE-2026-106116Medium· 5.3PoC
yesterday

ImageSharp is a 2D graphics library

ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, ExifReader.ReadValues64 trusts the 64-bit BigTIFF IFD entry count and iterates once per declared entry. When fewer than 20 bytes remain, ExifReader.ReadValue64 returns without …

▾ TwilightSixLabors · ImageSharpvia NVD
CVE-2026-106117High· 7.5PoC
yesterday

ImageSharp is a 2D graphics library

ImageSharp is a 2D graphics library. From 3.0.0 until 4.1.1, decoding a strip TIFF using CCITT Group 3 or Modified Huffman compression can pass attacker-expanded runs to BitWriterUtils.WriteBits without first checking the current row wid…

▾ MidnightSixLabors · ImageSharpvia NVD
SixLabors vulnerabilities (CVEs) · VulnSea