Use-after-free in ImageSharp - CVE-2024-27929
Published: March 5, 2024 / Updated: August 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information and cause a denial of service.
The vulnerability exists due to use-after-free in the ImageSharp image processing component when parsing a crafted image file. A remote attacker can trick the victim into opening a crafted file to disclose sensitive information and cause a denial of service.
User interaction is required to open a crafted file.