Out-of-bounds write in ImageSharp - #VU150206
Published: September 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds write in the TIFF CCITT Group 3 (T4) encoder when encoding narrow 1-bit images with CcittGroup3Fax compression. A remote attacker can cause unchecked writes beyond the compressed-data buffer to cause a denial of service.
The affected path may be reached when an application re-encodes TIFF input while retaining its compression and bit-depth metadata.