Infinite loop in ImageSharp - #VU150204
Published: September 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a loop with an unreachable exit condition in the ReadValues64 BigTIFF IFD entry parser when decoding a malformed BigTIFF image with a declared entry count exceeding the available entry data. A remote attacker can supply a crafted BigTIFF image with a large IFD entry count to cause a denial of service.