Sensitive Information in Resource Not Removed Before Reuse in ImageSharp - #VU150208
Published: September 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to sensitive information in a resource not removed before reuse in the ZIP-compressed OpenEXR decoder when processing a crafted OpenEXR image with a short non-empty inflate result. A remote attacker can supply a crafted ZIP-compressed OpenEXR image to disclose sensitive information.
The disclosure is process-local and can expose data from a completed prior ImageSharp operation when the shared Configuration.Default allocator is used and decoded pixels or derived output are exposed.