Out-of-bounds write in ImageSharp - #VU150207
Published: September 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds write in the ICC LUT16 CLUT and output-LUT conversion path when decoding an image containing a malformed embedded ICC profile with more than four output channels. A remote attacker can supply a specially crafted image to cause a denial of service.
Exploitation requires ICC conversion to be enabled through DecoderOptions.ColorProfileHandling set to Convert.