Out-of-bounds write in ImageSharp - #VU144573
Published: August 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds write in CCITT fax TIFF strip decompression via BitWriterUtils.WriteBits/WriteBit/WriteZeroBit when parsing an attacker-supplied fax-compressed strip TIFF image. A remote attacker can send a specially crafted TIFF file to cause a denial of service.
The issue affects strip TIFF images using Compression=2 or Compression=3, and no user interaction is required.