Uncontrolled Memory Allocation in ImageSharp - #VU150202
Published: September 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to excessive memory allocation in the ReadClutF32 ICC CLUT parser when processing a malformed embedded ICC profile. A remote attacker can supply an image containing a malformed ICC profile to cause a denial of service.
In version 4, the affected conversion path is reached only when ICC color-profile conversion is enabled.