SixLabors.ImageSharp
A modern, cross-platform, 2D Graphics library for .NET
Activity
- Latest release
- 3w ago
- Total releases
- 39
- Cadence
- ~35 days
- Last 12 months
- 5
Reach
- Stars
- 8.0k
Details
- License
- Apache-2.0
- First release
- Aug 04, 2020
| Version | Released | |
|---|---|---|
4.1.1
patch
| ||
4.1.0
minor
| ||
4.0.0
major
| ||
2.1.13
patch
| ||
3.1.12
patch
| ||
2.1.12
patch
| ||
2.1.11
patch
| ||
3.1.11
patch
| ||
3.1.10
patch
1 CVE
CVE-2025-54575
GHSA-rxmq-m78w-7wmc
Jul 30, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.11 or v2.1.11. WorkaroundsNone. Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 29 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.10
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
2.1.11
3.1.11
References
Updated Jul 31, 2025 · Source: OSV.dev | ||
3.1.9
patch
1 CVE
CVE-2025-54575
GHSA-rxmq-m78w-7wmc
Jul 30, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.11 or v2.1.11. WorkaroundsNone. Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 29 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.10
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
2.1.11
3.1.11
References
Updated Jul 31, 2025 · Source: OSV.dev | ||
3.1.8
patch
1 CVE
CVE-2025-54575
GHSA-rxmq-m78w-7wmc
Jul 30, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.11 or v2.1.11. WorkaroundsNone. Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 29 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.10
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
2.1.11
3.1.11
References
Updated Jul 31, 2025 · Source: OSV.dev | ||
2.1.10
patch
1 CVE
CVE-2025-54575
GHSA-rxmq-m78w-7wmc
Jul 30, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.11 or v2.1.11. WorkaroundsNone. Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 29 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.10
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
2.1.11
3.1.11
References
Updated Jul 31, 2025 · Source: OSV.dev | ||
3.1.7
patch
1 CVE
CVE-2025-54575
GHSA-rxmq-m78w-7wmc
Jul 30, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.11 or v2.1.11. WorkaroundsNone. Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 29 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.10
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
2.1.11
3.1.11
References
Updated Jul 31, 2025 · Source: OSV.dev | ||
3.1.6
patch
2 CVEs
CVE-2025-54575
GHSA-rxmq-m78w-7wmc
Jul 30, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.11 or v2.1.11. WorkaroundsNone. Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 29 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.10
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
2.1.11
3.1.11
References
Updated Jul 31, 2025 · Source: OSV.dev
CVE-2025-27598
GHSA-2cmq-823j-5qj8
Mar 06, 2025
Out-of-bounds Write in SixLabors ImageSharp
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/issues/2859 https://github.com/SixLabors/ImageSharp/issues/2890 Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
1.0.0
1.0.0-beta0001
+ 24 more Show less
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.10
3.1.7
References Updated Mar 07, 2025 · Source: OSV.dev | ||
2.1.9
patch
2 CVEs
CVE-2025-54575
GHSA-rxmq-m78w-7wmc
Jul 30, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.11 or v2.1.11. WorkaroundsNone. Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 29 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.10
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
2.1.11
3.1.11
References
Updated Jul 31, 2025 · Source: OSV.dev
CVE-2025-27598
GHSA-2cmq-823j-5qj8
Mar 06, 2025
Out-of-bounds Write in SixLabors ImageSharp
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/issues/2859 https://github.com/SixLabors/ImageSharp/issues/2890 Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
1.0.0
1.0.0-beta0001
+ 24 more Show less
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.10
3.1.7
References Updated Mar 07, 2025 · Source: OSV.dev | ||
3.1.5
patch
2 CVEs
CVE-2025-54575
GHSA-rxmq-m78w-7wmc
Jul 30, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.11 or v2.1.11. WorkaroundsNone. Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 29 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.10
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
2.1.11
3.1.11
References
Updated Jul 31, 2025 · Source: OSV.dev
CVE-2025-27598
GHSA-2cmq-823j-5qj8
Mar 06, 2025
Out-of-bounds Write in SixLabors ImageSharp
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/issues/2859 https://github.com/SixLabors/ImageSharp/issues/2890 Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
1.0.0
1.0.0-beta0001
+ 24 more Show less
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.10
3.1.7
References Updated Mar 07, 2025 · Source: OSV.dev | ||
3.1.4
patch
4 CVEs
CVE-2025-54575
GHSA-rxmq-m78w-7wmc
Jul 30, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.11 or v2.1.11. WorkaroundsNone. Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 29 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.10
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
2.1.11
3.1.11
References
Updated Jul 31, 2025 · Source: OSV.dev
CVE-2025-27598
GHSA-2cmq-823j-5qj8
Mar 06, 2025
Out-of-bounds Write in SixLabors ImageSharp
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/issues/2859 https://github.com/SixLabors/ImageSharp/issues/2890 Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
1.0.0
1.0.0-beta0001
+ 24 more Show less
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.10
3.1.7
References Updated Mar 07, 2025 · Source: OSV.dev
CVE-2024-41132
GHSA-qxrv-gp6x-rc23
Jul 22, 2024
SixLabors ImageSharp has Excessive Memory Allocation in Gif Decoder
Medium
Network
Low
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. PatchesHas the problem been patched? What versions should users upgrade to? The problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Before calling ReferencesAre there any links users can visit to find out more?
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41131
GHSA-63p8-c4ww-9cg7
Jul 22, 2024
SixLabors ImageSharp Out-of-bounds Write
High
Network
Low
None
None
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/pull/2754 https://github.com/SixLabors/ImageSharp/pull/2756 Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.8
patch
4 CVEs
CVE-2025-54575
GHSA-rxmq-m78w-7wmc
Jul 30, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.11 or v2.1.11. WorkaroundsNone. Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 29 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.10
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
2.1.11
3.1.11
References
Updated Jul 31, 2025 · Source: OSV.dev
CVE-2025-27598
GHSA-2cmq-823j-5qj8
Mar 06, 2025
Out-of-bounds Write in SixLabors ImageSharp
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/issues/2859 https://github.com/SixLabors/ImageSharp/issues/2890 Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
1.0.0
1.0.0-beta0001
+ 24 more Show less
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.10
3.1.7
References Updated Mar 07, 2025 · Source: OSV.dev
CVE-2024-41132
GHSA-qxrv-gp6x-rc23
Jul 22, 2024
SixLabors ImageSharp has Excessive Memory Allocation in Gif Decoder
Medium
Network
Low
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. PatchesHas the problem been patched? What versions should users upgrade to? The problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Before calling ReferencesAre there any links users can visit to find out more?
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41131
GHSA-63p8-c4ww-9cg7
Jul 22, 2024
SixLabors ImageSharp Out-of-bounds Write
High
Network
Low
None
None
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/pull/2754 https://github.com/SixLabors/ImageSharp/pull/2756 Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.7
patch
6 CVEs
CVE-2025-54575
GHSA-rxmq-m78w-7wmc
Jul 30, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.11 or v2.1.11. WorkaroundsNone. Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 29 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.10
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
2.1.11
3.1.11
References
Updated Jul 31, 2025 · Source: OSV.dev
CVE-2025-27598
GHSA-2cmq-823j-5qj8
Mar 06, 2025
Out-of-bounds Write in SixLabors ImageSharp
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/issues/2859 https://github.com/SixLabors/ImageSharp/issues/2890 Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
1.0.0
1.0.0-beta0001
+ 24 more Show less
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.10
3.1.7
References Updated Mar 07, 2025 · Source: OSV.dev
CVE-2024-41132
GHSA-qxrv-gp6x-rc23
Jul 22, 2024
SixLabors ImageSharp has Excessive Memory Allocation in Gif Decoder
Medium
Network
Low
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. PatchesHas the problem been patched? What versions should users upgrade to? The problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Before calling ReferencesAre there any links users can visit to find out more?
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41131
GHSA-63p8-c4ww-9cg7
Jul 22, 2024
SixLabors ImageSharp Out-of-bounds Write
High
Network
Low
None
None
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/pull/2754 https://github.com/SixLabors/ImageSharp/pull/2756 Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32036
GHSA-5x7m-6737-26cr
Apr 15, 2024
SixLabors.ImageSharp vulnerable to data leakage
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
High
None
None
ImpactA data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the resulting image buffer. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsNone ReferencesNone Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32035
GHSA-g85r-6x2q-45w7
Apr 15, 2024
SixLabors.ImageSharp vulnerable to Memory Allocation with Excessive Size Value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in image decoders. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. This flaw can be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on ImageSharp for image processing tasks. Users and administrators are advised to update to the latest version of ImageSharp that addresses this vulnerability to mitigate the risk of exploitation. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsBefore calling References
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.1.3
patch
6 CVEs
CVE-2025-54575
GHSA-rxmq-m78w-7wmc
Jul 30, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.11 or v2.1.11. WorkaroundsNone. Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 29 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.10
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
2.1.11
3.1.11
References
Updated Jul 31, 2025 · Source: OSV.dev
CVE-2025-27598
GHSA-2cmq-823j-5qj8
Mar 06, 2025
Out-of-bounds Write in SixLabors ImageSharp
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/issues/2859 https://github.com/SixLabors/ImageSharp/issues/2890 Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
1.0.0
1.0.0-beta0001
+ 24 more Show less
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.10
3.1.7
References Updated Mar 07, 2025 · Source: OSV.dev
CVE-2024-41132
GHSA-qxrv-gp6x-rc23
Jul 22, 2024
SixLabors ImageSharp has Excessive Memory Allocation in Gif Decoder
Medium
Network
Low
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. PatchesHas the problem been patched? What versions should users upgrade to? The problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Before calling ReferencesAre there any links users can visit to find out more?
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41131
GHSA-63p8-c4ww-9cg7
Jul 22, 2024
SixLabors ImageSharp Out-of-bounds Write
High
Network
Low
None
None
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/pull/2754 https://github.com/SixLabors/ImageSharp/pull/2756 Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32036
GHSA-5x7m-6737-26cr
Apr 15, 2024
SixLabors.ImageSharp vulnerable to data leakage
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
High
None
None
ImpactA data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the resulting image buffer. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsNone ReferencesNone Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32035
GHSA-g85r-6x2q-45w7
Apr 15, 2024
SixLabors.ImageSharp vulnerable to Memory Allocation with Excessive Size Value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in image decoders. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. This flaw can be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on ImageSharp for image processing tasks. Users and administrators are advised to update to the latest version of ImageSharp that addresses this vulnerability to mitigate the risk of exploitation. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsBefore calling References
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.1.2
patch
7 CVEs
CVE-2025-54575
GHSA-rxmq-m78w-7wmc
Jul 30, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.11 or v2.1.11. WorkaroundsNone. Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 29 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.10
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
2.1.11
3.1.11
References
Updated Jul 31, 2025 · Source: OSV.dev
CVE-2025-27598
GHSA-2cmq-823j-5qj8
Mar 06, 2025
Out-of-bounds Write in SixLabors ImageSharp
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/issues/2859 https://github.com/SixLabors/ImageSharp/issues/2890 Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
1.0.0
1.0.0-beta0001
+ 24 more Show less
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.10
3.1.7
References Updated Mar 07, 2025 · Source: OSV.dev
CVE-2024-41132
GHSA-qxrv-gp6x-rc23
Jul 22, 2024
SixLabors ImageSharp has Excessive Memory Allocation in Gif Decoder
Medium
Network
Low
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. PatchesHas the problem been patched? What versions should users upgrade to? The problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Before calling ReferencesAre there any links users can visit to find out more?
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41131
GHSA-63p8-c4ww-9cg7
Jul 22, 2024
SixLabors ImageSharp Out-of-bounds Write
High
Network
Low
None
None
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/pull/2754 https://github.com/SixLabors/ImageSharp/pull/2756 Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32036
GHSA-5x7m-6737-26cr
Apr 15, 2024
SixLabors.ImageSharp vulnerable to data leakage
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
High
None
None
ImpactA data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the resulting image buffer. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsNone ReferencesNone Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32035
GHSA-g85r-6x2q-45w7
Apr 15, 2024
SixLabors.ImageSharp vulnerable to Memory Allocation with Excessive Size Value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in image decoders. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. This flaw can be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on ImageSharp for image processing tasks. Users and administrators are advised to update to the latest version of ImageSharp that addresses this vulnerability to mitigate the risk of exploitation. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsBefore calling References
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27929
GHSA-65x7-c272-7g7r
Mar 05, 2024
Use After Free in SixLabors.ImageSharp
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
ImpactA heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when an attacker passes a specially crafted PNG image file to ImageSharp for conversion, potentially leading to information disclosure. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.3 or v2.1.7. WorkaroundsNone ReferencesNone Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
+ 17 more Show less
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
3.1.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
3.1.1
patch
7 CVEs
CVE-2025-54575
GHSA-rxmq-m78w-7wmc
Jul 30, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.11 or v2.1.11. WorkaroundsNone. Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 29 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.10
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
2.1.11
3.1.11
References
Updated Jul 31, 2025 · Source: OSV.dev
CVE-2025-27598
GHSA-2cmq-823j-5qj8
Mar 06, 2025
Out-of-bounds Write in SixLabors ImageSharp
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/issues/2859 https://github.com/SixLabors/ImageSharp/issues/2890 Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
1.0.0
1.0.0-beta0001
+ 24 more Show less
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.10
3.1.7
References Updated Mar 07, 2025 · Source: OSV.dev
CVE-2024-41132
GHSA-qxrv-gp6x-rc23
Jul 22, 2024
SixLabors ImageSharp has Excessive Memory Allocation in Gif Decoder
Medium
Network
Low
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. PatchesHas the problem been patched? What versions should users upgrade to? The problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Before calling ReferencesAre there any links users can visit to find out more?
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41131
GHSA-63p8-c4ww-9cg7
Jul 22, 2024
SixLabors ImageSharp Out-of-bounds Write
High
Network
Low
None
None
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/pull/2754 https://github.com/SixLabors/ImageSharp/pull/2756 Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32036
GHSA-5x7m-6737-26cr
Apr 15, 2024
SixLabors.ImageSharp vulnerable to data leakage
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
High
None
None
ImpactA data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the resulting image buffer. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsNone ReferencesNone Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32035
GHSA-g85r-6x2q-45w7
Apr 15, 2024
SixLabors.ImageSharp vulnerable to Memory Allocation with Excessive Size Value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in image decoders. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. This flaw can be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on ImageSharp for image processing tasks. Users and administrators are advised to update to the latest version of ImageSharp that addresses this vulnerability to mitigate the risk of exploitation. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsBefore calling References
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27929
GHSA-65x7-c272-7g7r
Mar 05, 2024
Use After Free in SixLabors.ImageSharp
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
ImpactA heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when an attacker passes a specially crafted PNG image file to ImageSharp for conversion, potentially leading to information disclosure. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.3 or v2.1.7. WorkaroundsNone ReferencesNone Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
+ 17 more Show less
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
3.1.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
3.1.0
minor
7 CVEs
CVE-2025-54575
GHSA-rxmq-m78w-7wmc
Jul 30, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.11 or v2.1.11. WorkaroundsNone. Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 29 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.10
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
2.1.11
3.1.11
References
Updated Jul 31, 2025 · Source: OSV.dev
CVE-2025-27598
GHSA-2cmq-823j-5qj8
Mar 06, 2025
Out-of-bounds Write in SixLabors ImageSharp
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/issues/2859 https://github.com/SixLabors/ImageSharp/issues/2890 Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
1.0.0
1.0.0-beta0001
+ 24 more Show less
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.10
3.1.7
References Updated Mar 07, 2025 · Source: OSV.dev
CVE-2024-41132
GHSA-qxrv-gp6x-rc23
Jul 22, 2024
SixLabors ImageSharp has Excessive Memory Allocation in Gif Decoder
Medium
Network
Low
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. PatchesHas the problem been patched? What versions should users upgrade to? The problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Before calling ReferencesAre there any links users can visit to find out more?
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41131
GHSA-63p8-c4ww-9cg7
Jul 22, 2024
SixLabors ImageSharp Out-of-bounds Write
High
Network
Low
None
None
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/pull/2754 https://github.com/SixLabors/ImageSharp/pull/2756 Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32036
GHSA-5x7m-6737-26cr
Apr 15, 2024
SixLabors.ImageSharp vulnerable to data leakage
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
High
None
None
ImpactA data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the resulting image buffer. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsNone ReferencesNone Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32035
GHSA-g85r-6x2q-45w7
Apr 15, 2024
SixLabors.ImageSharp vulnerable to Memory Allocation with Excessive Size Value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in image decoders. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. This flaw can be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on ImageSharp for image processing tasks. Users and administrators are advised to update to the latest version of ImageSharp that addresses this vulnerability to mitigate the risk of exploitation. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsBefore calling References
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27929
GHSA-65x7-c272-7g7r
Mar 05, 2024
Use After Free in SixLabors.ImageSharp
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
ImpactA heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when an attacker passes a specially crafted PNG image file to ImageSharp for conversion, potentially leading to information disclosure. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.3 or v2.1.7. WorkaroundsNone ReferencesNone Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
+ 17 more Show less
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
3.1.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.6
patch
7 CVEs
CVE-2025-54575
GHSA-rxmq-m78w-7wmc
Jul 30, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.11 or v2.1.11. WorkaroundsNone. Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 29 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.10
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
2.1.11
3.1.11
References
Updated Jul 31, 2025 · Source: OSV.dev
CVE-2025-27598
GHSA-2cmq-823j-5qj8
Mar 06, 2025
Out-of-bounds Write in SixLabors ImageSharp
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/issues/2859 https://github.com/SixLabors/ImageSharp/issues/2890 Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
1.0.0
1.0.0-beta0001
+ 24 more Show less
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.10
3.1.7
References Updated Mar 07, 2025 · Source: OSV.dev
CVE-2024-41132
GHSA-qxrv-gp6x-rc23
Jul 22, 2024
SixLabors ImageSharp has Excessive Memory Allocation in Gif Decoder
Medium
Network
Low
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. PatchesHas the problem been patched? What versions should users upgrade to? The problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Before calling ReferencesAre there any links users can visit to find out more?
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41131
GHSA-63p8-c4ww-9cg7
Jul 22, 2024
SixLabors ImageSharp Out-of-bounds Write
High
Network
Low
None
None
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/pull/2754 https://github.com/SixLabors/ImageSharp/pull/2756 Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32036
GHSA-5x7m-6737-26cr
Apr 15, 2024
SixLabors.ImageSharp vulnerable to data leakage
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
High
None
None
ImpactA data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the resulting image buffer. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsNone ReferencesNone Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32035
GHSA-g85r-6x2q-45w7
Apr 15, 2024
SixLabors.ImageSharp vulnerable to Memory Allocation with Excessive Size Value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in image decoders. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. This flaw can be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on ImageSharp for image processing tasks. Users and administrators are advised to update to the latest version of ImageSharp that addresses this vulnerability to mitigate the risk of exploitation. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsBefore calling References
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27929
GHSA-65x7-c272-7g7r
Mar 05, 2024
Use After Free in SixLabors.ImageSharp
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
ImpactA heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when an attacker passes a specially crafted PNG image file to ImageSharp for conversion, potentially leading to information disclosure. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.3 or v2.1.7. WorkaroundsNone ReferencesNone Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
+ 17 more Show less
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
3.1.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
3.0.2
patch
7 CVEs
CVE-2025-54575
GHSA-rxmq-m78w-7wmc
Jul 30, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.11 or v2.1.11. WorkaroundsNone. Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 29 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.10
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
2.1.11
3.1.11
References
Updated Jul 31, 2025 · Source: OSV.dev
CVE-2025-27598
GHSA-2cmq-823j-5qj8
Mar 06, 2025
Out-of-bounds Write in SixLabors ImageSharp
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/issues/2859 https://github.com/SixLabors/ImageSharp/issues/2890 Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
1.0.0
1.0.0-beta0001
+ 24 more Show less
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.10
3.1.7
References Updated Mar 07, 2025 · Source: OSV.dev
CVE-2024-41132
GHSA-qxrv-gp6x-rc23
Jul 22, 2024
SixLabors ImageSharp has Excessive Memory Allocation in Gif Decoder
Medium
Network
Low
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. PatchesHas the problem been patched? What versions should users upgrade to? The problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Before calling ReferencesAre there any links users can visit to find out more?
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41131
GHSA-63p8-c4ww-9cg7
Jul 22, 2024
SixLabors ImageSharp Out-of-bounds Write
High
Network
Low
None
None
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/pull/2754 https://github.com/SixLabors/ImageSharp/pull/2756 Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32036
GHSA-5x7m-6737-26cr
Apr 15, 2024
SixLabors.ImageSharp vulnerable to data leakage
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
High
None
None
ImpactA data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the resulting image buffer. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsNone ReferencesNone Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32035
GHSA-g85r-6x2q-45w7
Apr 15, 2024
SixLabors.ImageSharp vulnerable to Memory Allocation with Excessive Size Value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in image decoders. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. This flaw can be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on ImageSharp for image processing tasks. Users and administrators are advised to update to the latest version of ImageSharp that addresses this vulnerability to mitigate the risk of exploitation. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsBefore calling References
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27929
GHSA-65x7-c272-7g7r
Mar 05, 2024
Use After Free in SixLabors.ImageSharp
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
ImpactA heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when an attacker passes a specially crafted PNG image file to ImageSharp for conversion, potentially leading to information disclosure. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.3 or v2.1.7. WorkaroundsNone ReferencesNone Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
+ 17 more Show less
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
3.1.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.5
patch
7 CVEs
CVE-2025-54575
GHSA-rxmq-m78w-7wmc
Jul 30, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.11 or v2.1.11. WorkaroundsNone. Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 29 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.10
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
2.1.11
3.1.11
References
Updated Jul 31, 2025 · Source: OSV.dev
CVE-2025-27598
GHSA-2cmq-823j-5qj8
Mar 06, 2025
Out-of-bounds Write in SixLabors ImageSharp
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/issues/2859 https://github.com/SixLabors/ImageSharp/issues/2890 Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
1.0.0
1.0.0-beta0001
+ 24 more Show less
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.10
3.1.7
References Updated Mar 07, 2025 · Source: OSV.dev
CVE-2024-41132
GHSA-qxrv-gp6x-rc23
Jul 22, 2024
SixLabors ImageSharp has Excessive Memory Allocation in Gif Decoder
Medium
Network
Low
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. PatchesHas the problem been patched? What versions should users upgrade to? The problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Before calling ReferencesAre there any links users can visit to find out more?
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41131
GHSA-63p8-c4ww-9cg7
Jul 22, 2024
SixLabors ImageSharp Out-of-bounds Write
High
Network
Low
None
None
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/pull/2754 https://github.com/SixLabors/ImageSharp/pull/2756 Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32036
GHSA-5x7m-6737-26cr
Apr 15, 2024
SixLabors.ImageSharp vulnerable to data leakage
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
High
None
None
ImpactA data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the resulting image buffer. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsNone ReferencesNone Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32035
GHSA-g85r-6x2q-45w7
Apr 15, 2024
SixLabors.ImageSharp vulnerable to Memory Allocation with Excessive Size Value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in image decoders. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. This flaw can be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on ImageSharp for image processing tasks. Users and administrators are advised to update to the latest version of ImageSharp that addresses this vulnerability to mitigate the risk of exploitation. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsBefore calling References
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27929
GHSA-65x7-c272-7g7r
Mar 05, 2024
Use After Free in SixLabors.ImageSharp
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
ImpactA heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when an attacker passes a specially crafted PNG image file to ImageSharp for conversion, potentially leading to information disclosure. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.3 or v2.1.7. WorkaroundsNone ReferencesNone Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
+ 17 more Show less
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
3.1.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
3.0.1
patch
7 CVEs
CVE-2025-54575
GHSA-rxmq-m78w-7wmc
Jul 30, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.11 or v2.1.11. WorkaroundsNone. Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 29 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.10
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
2.1.11
3.1.11
References
Updated Jul 31, 2025 · Source: OSV.dev
CVE-2025-27598
GHSA-2cmq-823j-5qj8
Mar 06, 2025
Out-of-bounds Write in SixLabors ImageSharp
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/issues/2859 https://github.com/SixLabors/ImageSharp/issues/2890 Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
1.0.0
1.0.0-beta0001
+ 24 more Show less
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.10
3.1.7
References Updated Mar 07, 2025 · Source: OSV.dev
CVE-2024-41132
GHSA-qxrv-gp6x-rc23
Jul 22, 2024
SixLabors ImageSharp has Excessive Memory Allocation in Gif Decoder
Medium
Network
Low
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. PatchesHas the problem been patched? What versions should users upgrade to? The problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Before calling ReferencesAre there any links users can visit to find out more?
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41131
GHSA-63p8-c4ww-9cg7
Jul 22, 2024
SixLabors ImageSharp Out-of-bounds Write
High
Network
Low
None
None
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/pull/2754 https://github.com/SixLabors/ImageSharp/pull/2756 Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32036
GHSA-5x7m-6737-26cr
Apr 15, 2024
SixLabors.ImageSharp vulnerable to data leakage
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
High
None
None
ImpactA data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the resulting image buffer. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsNone ReferencesNone Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32035
GHSA-g85r-6x2q-45w7
Apr 15, 2024
SixLabors.ImageSharp vulnerable to Memory Allocation with Excessive Size Value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in image decoders. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. This flaw can be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on ImageSharp for image processing tasks. Users and administrators are advised to update to the latest version of ImageSharp that addresses this vulnerability to mitigate the risk of exploitation. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsBefore calling References
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27929
GHSA-65x7-c272-7g7r
Mar 05, 2024
Use After Free in SixLabors.ImageSharp
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
ImpactA heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when an attacker passes a specially crafted PNG image file to ImageSharp for conversion, potentially leading to information disclosure. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.3 or v2.1.7. WorkaroundsNone ReferencesNone Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
+ 17 more Show less
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
3.1.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.4
patch
7 CVEs
CVE-2025-54575
GHSA-rxmq-m78w-7wmc
Jul 30, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.11 or v2.1.11. WorkaroundsNone. Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 29 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.10
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
2.1.11
3.1.11
References
Updated Jul 31, 2025 · Source: OSV.dev
CVE-2025-27598
GHSA-2cmq-823j-5qj8
Mar 06, 2025
Out-of-bounds Write in SixLabors ImageSharp
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/issues/2859 https://github.com/SixLabors/ImageSharp/issues/2890 Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
1.0.0
1.0.0-beta0001
+ 24 more Show less
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.10
3.1.7
References Updated Mar 07, 2025 · Source: OSV.dev
CVE-2024-41132
GHSA-qxrv-gp6x-rc23
Jul 22, 2024
SixLabors ImageSharp has Excessive Memory Allocation in Gif Decoder
Medium
Network
Low
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. PatchesHas the problem been patched? What versions should users upgrade to? The problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Before calling ReferencesAre there any links users can visit to find out more?
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41131
GHSA-63p8-c4ww-9cg7
Jul 22, 2024
SixLabors ImageSharp Out-of-bounds Write
High
Network
Low
None
None
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/pull/2754 https://github.com/SixLabors/ImageSharp/pull/2756 Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32036
GHSA-5x7m-6737-26cr
Apr 15, 2024
SixLabors.ImageSharp vulnerable to data leakage
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
High
None
None
ImpactA data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the resulting image buffer. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsNone ReferencesNone Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32035
GHSA-g85r-6x2q-45w7
Apr 15, 2024
SixLabors.ImageSharp vulnerable to Memory Allocation with Excessive Size Value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in image decoders. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. This flaw can be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on ImageSharp for image processing tasks. Users and administrators are advised to update to the latest version of ImageSharp that addresses this vulnerability to mitigate the risk of exploitation. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsBefore calling References
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27929
GHSA-65x7-c272-7g7r
Mar 05, 2024
Use After Free in SixLabors.ImageSharp
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
ImpactA heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when an attacker passes a specially crafted PNG image file to ImageSharp for conversion, potentially leading to information disclosure. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.3 or v2.1.7. WorkaroundsNone ReferencesNone Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
+ 17 more Show less
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
3.1.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
3.0.0
major
7 CVEs
CVE-2025-54575
GHSA-rxmq-m78w-7wmc
Jul 30, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.11 or v2.1.11. WorkaroundsNone. Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 29 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.10
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
2.1.11
3.1.11
References
Updated Jul 31, 2025 · Source: OSV.dev
CVE-2025-27598
GHSA-2cmq-823j-5qj8
Mar 06, 2025
Out-of-bounds Write in SixLabors ImageSharp
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/issues/2859 https://github.com/SixLabors/ImageSharp/issues/2890 Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
1.0.0
1.0.0-beta0001
+ 24 more Show less
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.10
3.1.7
References Updated Mar 07, 2025 · Source: OSV.dev
CVE-2024-41132
GHSA-qxrv-gp6x-rc23
Jul 22, 2024
SixLabors ImageSharp has Excessive Memory Allocation in Gif Decoder
Medium
Network
Low
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. PatchesHas the problem been patched? What versions should users upgrade to? The problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Before calling ReferencesAre there any links users can visit to find out more?
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41131
GHSA-63p8-c4ww-9cg7
Jul 22, 2024
SixLabors ImageSharp Out-of-bounds Write
High
Network
Low
None
None
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/pull/2754 https://github.com/SixLabors/ImageSharp/pull/2756 Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32036
GHSA-5x7m-6737-26cr
Apr 15, 2024
SixLabors.ImageSharp vulnerable to data leakage
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
High
None
None
ImpactA data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the resulting image buffer. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsNone ReferencesNone Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32035
GHSA-g85r-6x2q-45w7
Apr 15, 2024
SixLabors.ImageSharp vulnerable to Memory Allocation with Excessive Size Value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in image decoders. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. This flaw can be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on ImageSharp for image processing tasks. Users and administrators are advised to update to the latest version of ImageSharp that addresses this vulnerability to mitigate the risk of exploitation. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsBefore calling References
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27929
GHSA-65x7-c272-7g7r
Mar 05, 2024
Use After Free in SixLabors.ImageSharp
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
ImpactA heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when an attacker passes a specially crafted PNG image file to ImageSharp for conversion, potentially leading to information disclosure. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.3 or v2.1.7. WorkaroundsNone ReferencesNone Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
+ 17 more Show less
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
3.1.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.3
patch
7 CVEs
CVE-2025-54575
GHSA-rxmq-m78w-7wmc
Jul 30, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.11 or v2.1.11. WorkaroundsNone. Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 29 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.10
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
2.1.11
3.1.11
References
Updated Jul 31, 2025 · Source: OSV.dev
CVE-2025-27598
GHSA-2cmq-823j-5qj8
Mar 06, 2025
Out-of-bounds Write in SixLabors ImageSharp
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/issues/2859 https://github.com/SixLabors/ImageSharp/issues/2890 Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
1.0.0
1.0.0-beta0001
+ 24 more Show less
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.10
3.1.7
References Updated Mar 07, 2025 · Source: OSV.dev
CVE-2024-41132
GHSA-qxrv-gp6x-rc23
Jul 22, 2024
SixLabors ImageSharp has Excessive Memory Allocation in Gif Decoder
Medium
Network
Low
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. PatchesHas the problem been patched? What versions should users upgrade to? The problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Before calling ReferencesAre there any links users can visit to find out more?
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41131
GHSA-63p8-c4ww-9cg7
Jul 22, 2024
SixLabors ImageSharp Out-of-bounds Write
High
Network
Low
None
None
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/pull/2754 https://github.com/SixLabors/ImageSharp/pull/2756 Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32036
GHSA-5x7m-6737-26cr
Apr 15, 2024
SixLabors.ImageSharp vulnerable to data leakage
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
High
None
None
ImpactA data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the resulting image buffer. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsNone ReferencesNone Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32035
GHSA-g85r-6x2q-45w7
Apr 15, 2024
SixLabors.ImageSharp vulnerable to Memory Allocation with Excessive Size Value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in image decoders. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. This flaw can be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on ImageSharp for image processing tasks. Users and administrators are advised to update to the latest version of ImageSharp that addresses this vulnerability to mitigate the risk of exploitation. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsBefore calling References
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27929
GHSA-65x7-c272-7g7r
Mar 05, 2024
Use After Free in SixLabors.ImageSharp
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
ImpactA heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when an attacker passes a specially crafted PNG image file to ImageSharp for conversion, potentially leading to information disclosure. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.3 or v2.1.7. WorkaroundsNone ReferencesNone Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
+ 17 more Show less
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
3.1.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.2
patch
7 CVEs
CVE-2025-54575
GHSA-rxmq-m78w-7wmc
Jul 30, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.11 or v2.1.11. WorkaroundsNone. Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 29 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.10
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
2.1.11
3.1.11
References
Updated Jul 31, 2025 · Source: OSV.dev
CVE-2025-27598
GHSA-2cmq-823j-5qj8
Mar 06, 2025
Out-of-bounds Write in SixLabors ImageSharp
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/issues/2859 https://github.com/SixLabors/ImageSharp/issues/2890 Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
1.0.0
1.0.0-beta0001
+ 24 more Show less
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.10
3.1.7
References Updated Mar 07, 2025 · Source: OSV.dev
CVE-2024-41132
GHSA-qxrv-gp6x-rc23
Jul 22, 2024
SixLabors ImageSharp has Excessive Memory Allocation in Gif Decoder
Medium
Network
Low
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. PatchesHas the problem been patched? What versions should users upgrade to? The problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Before calling ReferencesAre there any links users can visit to find out more?
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41131
GHSA-63p8-c4ww-9cg7
Jul 22, 2024
SixLabors ImageSharp Out-of-bounds Write
High
Network
Low
None
None
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/pull/2754 https://github.com/SixLabors/ImageSharp/pull/2756 Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32036
GHSA-5x7m-6737-26cr
Apr 15, 2024
SixLabors.ImageSharp vulnerable to data leakage
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
High
None
None
ImpactA data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the resulting image buffer. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsNone ReferencesNone Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32035
GHSA-g85r-6x2q-45w7
Apr 15, 2024
SixLabors.ImageSharp vulnerable to Memory Allocation with Excessive Size Value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in image decoders. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. This flaw can be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on ImageSharp for image processing tasks. Users and administrators are advised to update to the latest version of ImageSharp that addresses this vulnerability to mitigate the risk of exploitation. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsBefore calling References
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27929
GHSA-65x7-c272-7g7r
Mar 05, 2024
Use After Free in SixLabors.ImageSharp
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
ImpactA heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when an attacker passes a specially crafted PNG image file to ImageSharp for conversion, potentially leading to information disclosure. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.3 or v2.1.7. WorkaroundsNone ReferencesNone Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
+ 17 more Show less
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
3.1.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.1
patch
7 CVEs
CVE-2025-54575
GHSA-rxmq-m78w-7wmc
Jul 30, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.11 or v2.1.11. WorkaroundsNone. Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 29 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.10
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
2.1.11
3.1.11
References
Updated Jul 31, 2025 · Source: OSV.dev
CVE-2025-27598
GHSA-2cmq-823j-5qj8
Mar 06, 2025
Out-of-bounds Write in SixLabors ImageSharp
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/issues/2859 https://github.com/SixLabors/ImageSharp/issues/2890 Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
1.0.0
1.0.0-beta0001
+ 24 more Show less
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.10
3.1.7
References Updated Mar 07, 2025 · Source: OSV.dev
CVE-2024-41132
GHSA-qxrv-gp6x-rc23
Jul 22, 2024
SixLabors ImageSharp has Excessive Memory Allocation in Gif Decoder
Medium
Network
Low
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. PatchesHas the problem been patched? What versions should users upgrade to? The problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Before calling ReferencesAre there any links users can visit to find out more?
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41131
GHSA-63p8-c4ww-9cg7
Jul 22, 2024
SixLabors ImageSharp Out-of-bounds Write
High
Network
Low
None
None
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/pull/2754 https://github.com/SixLabors/ImageSharp/pull/2756 Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32036
GHSA-5x7m-6737-26cr
Apr 15, 2024
SixLabors.ImageSharp vulnerable to data leakage
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
High
None
None
ImpactA data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the resulting image buffer. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsNone ReferencesNone Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32035
GHSA-g85r-6x2q-45w7
Apr 15, 2024
SixLabors.ImageSharp vulnerable to Memory Allocation with Excessive Size Value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in image decoders. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. This flaw can be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on ImageSharp for image processing tasks. Users and administrators are advised to update to the latest version of ImageSharp that addresses this vulnerability to mitigate the risk of exploitation. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsBefore calling References
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27929
GHSA-65x7-c272-7g7r
Mar 05, 2024
Use After Free in SixLabors.ImageSharp
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
ImpactA heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when an attacker passes a specially crafted PNG image file to ImageSharp for conversion, potentially leading to information disclosure. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.3 or v2.1.7. WorkaroundsNone ReferencesNone Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
+ 17 more Show less
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
3.1.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.0
minor
7 CVEs
CVE-2025-54575
GHSA-rxmq-m78w-7wmc
Jul 30, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.11 or v2.1.11. WorkaroundsNone. Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 29 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.10
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
2.1.11
3.1.11
References
Updated Jul 31, 2025 · Source: OSV.dev
CVE-2025-27598
GHSA-2cmq-823j-5qj8
Mar 06, 2025
Out-of-bounds Write in SixLabors ImageSharp
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/issues/2859 https://github.com/SixLabors/ImageSharp/issues/2890 Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
1.0.0
1.0.0-beta0001
+ 24 more Show less
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.10
3.1.7
References Updated Mar 07, 2025 · Source: OSV.dev
CVE-2024-41132
GHSA-qxrv-gp6x-rc23
Jul 22, 2024
SixLabors ImageSharp has Excessive Memory Allocation in Gif Decoder
Medium
Network
Low
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. PatchesHas the problem been patched? What versions should users upgrade to? The problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Before calling ReferencesAre there any links users can visit to find out more?
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41131
GHSA-63p8-c4ww-9cg7
Jul 22, 2024
SixLabors ImageSharp Out-of-bounds Write
High
Network
Low
None
None
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/pull/2754 https://github.com/SixLabors/ImageSharp/pull/2756 Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32036
GHSA-5x7m-6737-26cr
Apr 15, 2024
SixLabors.ImageSharp vulnerable to data leakage
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
High
None
None
ImpactA data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the resulting image buffer. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsNone ReferencesNone Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32035
GHSA-g85r-6x2q-45w7
Apr 15, 2024
SixLabors.ImageSharp vulnerable to Memory Allocation with Excessive Size Value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in image decoders. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. This flaw can be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on ImageSharp for image processing tasks. Users and administrators are advised to update to the latest version of ImageSharp that addresses this vulnerability to mitigate the risk of exploitation. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsBefore calling References
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27929
GHSA-65x7-c272-7g7r
Mar 05, 2024
Use After Free in SixLabors.ImageSharp
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
ImpactA heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when an attacker passes a specially crafted PNG image file to ImageSharp for conversion, potentially leading to information disclosure. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.3 or v2.1.7. WorkaroundsNone ReferencesNone Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
+ 17 more Show less
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
3.1.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.0
major
7 CVEs
CVE-2025-54575
GHSA-rxmq-m78w-7wmc
Jul 30, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.11 or v2.1.11. WorkaroundsNone. Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 29 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.10
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
2.1.11
3.1.11
References
Updated Jul 31, 2025 · Source: OSV.dev
CVE-2025-27598
GHSA-2cmq-823j-5qj8
Mar 06, 2025
Out-of-bounds Write in SixLabors ImageSharp
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/issues/2859 https://github.com/SixLabors/ImageSharp/issues/2890 Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
1.0.0
1.0.0-beta0001
+ 24 more Show less
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.10
3.1.7
References Updated Mar 07, 2025 · Source: OSV.dev
CVE-2024-41132
GHSA-qxrv-gp6x-rc23
Jul 22, 2024
SixLabors ImageSharp has Excessive Memory Allocation in Gif Decoder
Medium
Network
Low
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. PatchesHas the problem been patched? What versions should users upgrade to? The problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Before calling ReferencesAre there any links users can visit to find out more?
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41131
GHSA-63p8-c4ww-9cg7
Jul 22, 2024
SixLabors ImageSharp Out-of-bounds Write
High
Network
Low
None
None
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/pull/2754 https://github.com/SixLabors/ImageSharp/pull/2756 Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32036
GHSA-5x7m-6737-26cr
Apr 15, 2024
SixLabors.ImageSharp vulnerable to data leakage
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
High
None
None
ImpactA data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the resulting image buffer. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsNone ReferencesNone Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32035
GHSA-g85r-6x2q-45w7
Apr 15, 2024
SixLabors.ImageSharp vulnerable to Memory Allocation with Excessive Size Value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in image decoders. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. This flaw can be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on ImageSharp for image processing tasks. Users and administrators are advised to update to the latest version of ImageSharp that addresses this vulnerability to mitigate the risk of exploitation. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsBefore calling References
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27929
GHSA-65x7-c272-7g7r
Mar 05, 2024
Use After Free in SixLabors.ImageSharp
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
ImpactA heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when an attacker passes a specially crafted PNG image file to ImageSharp for conversion, potentially leading to information disclosure. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.3 or v2.1.7. WorkaroundsNone ReferencesNone Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
+ 17 more Show less
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
3.1.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
1.0.4
patch
7 CVEs
CVE-2025-54575
GHSA-rxmq-m78w-7wmc
Jul 30, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.11 or v2.1.11. WorkaroundsNone. Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 29 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.10
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
2.1.11
3.1.11
References
Updated Jul 31, 2025 · Source: OSV.dev
CVE-2025-27598
GHSA-2cmq-823j-5qj8
Mar 06, 2025
Out-of-bounds Write in SixLabors ImageSharp
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/issues/2859 https://github.com/SixLabors/ImageSharp/issues/2890 Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
1.0.0
1.0.0-beta0001
+ 24 more Show less
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.10
3.1.7
References Updated Mar 07, 2025 · Source: OSV.dev
CVE-2024-41132
GHSA-qxrv-gp6x-rc23
Jul 22, 2024
SixLabors ImageSharp has Excessive Memory Allocation in Gif Decoder
Medium
Network
Low
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. PatchesHas the problem been patched? What versions should users upgrade to? The problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Before calling ReferencesAre there any links users can visit to find out more?
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41131
GHSA-63p8-c4ww-9cg7
Jul 22, 2024
SixLabors ImageSharp Out-of-bounds Write
High
Network
Low
None
None
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/pull/2754 https://github.com/SixLabors/ImageSharp/pull/2756 Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32036
GHSA-5x7m-6737-26cr
Apr 15, 2024
SixLabors.ImageSharp vulnerable to data leakage
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
High
None
None
ImpactA data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the resulting image buffer. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsNone ReferencesNone Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32035
GHSA-g85r-6x2q-45w7
Apr 15, 2024
SixLabors.ImageSharp vulnerable to Memory Allocation with Excessive Size Value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in image decoders. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. This flaw can be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on ImageSharp for image processing tasks. Users and administrators are advised to update to the latest version of ImageSharp that addresses this vulnerability to mitigate the risk of exploitation. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsBefore calling References
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27929
GHSA-65x7-c272-7g7r
Mar 05, 2024
Use After Free in SixLabors.ImageSharp
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
ImpactA heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when an attacker passes a specially crafted PNG image file to ImageSharp for conversion, potentially leading to information disclosure. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.3 or v2.1.7. WorkaroundsNone ReferencesNone Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
+ 17 more Show less
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
3.1.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.0.4
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.0.3
patch
7 CVEs
CVE-2025-54575
GHSA-rxmq-m78w-7wmc
Jul 30, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.11 or v2.1.11. WorkaroundsNone. Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 29 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.10
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
2.1.11
3.1.11
References
Updated Jul 31, 2025 · Source: OSV.dev
CVE-2025-27598
GHSA-2cmq-823j-5qj8
Mar 06, 2025
Out-of-bounds Write in SixLabors ImageSharp
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/issues/2859 https://github.com/SixLabors/ImageSharp/issues/2890 Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
1.0.0
1.0.0-beta0001
+ 24 more Show less
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.10
3.1.7
References Updated Mar 07, 2025 · Source: OSV.dev
CVE-2024-41132
GHSA-qxrv-gp6x-rc23
Jul 22, 2024
SixLabors ImageSharp has Excessive Memory Allocation in Gif Decoder
Medium
Network
Low
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. PatchesHas the problem been patched? What versions should users upgrade to? The problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Before calling ReferencesAre there any links users can visit to find out more?
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41131
GHSA-63p8-c4ww-9cg7
Jul 22, 2024
SixLabors ImageSharp Out-of-bounds Write
High
Network
Low
None
None
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/pull/2754 https://github.com/SixLabors/ImageSharp/pull/2756 Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32036
GHSA-5x7m-6737-26cr
Apr 15, 2024
SixLabors.ImageSharp vulnerable to data leakage
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
High
None
None
ImpactA data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the resulting image buffer. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsNone ReferencesNone Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32035
GHSA-g85r-6x2q-45w7
Apr 15, 2024
SixLabors.ImageSharp vulnerable to Memory Allocation with Excessive Size Value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in image decoders. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. This flaw can be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on ImageSharp for image processing tasks. Users and administrators are advised to update to the latest version of ImageSharp that addresses this vulnerability to mitigate the risk of exploitation. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsBefore calling References
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27929
GHSA-65x7-c272-7g7r
Mar 05, 2024
Use After Free in SixLabors.ImageSharp
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
ImpactA heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when an attacker passes a specially crafted PNG image file to ImageSharp for conversion, potentially leading to information disclosure. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.3 or v2.1.7. WorkaroundsNone ReferencesNone Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
+ 17 more Show less
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
3.1.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.0.3
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.0.2
patch
7 CVEs
CVE-2025-54575
GHSA-rxmq-m78w-7wmc
Jul 30, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.11 or v2.1.11. WorkaroundsNone. Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 29 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.10
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
2.1.11
3.1.11
References
Updated Jul 31, 2025 · Source: OSV.dev
CVE-2025-27598
GHSA-2cmq-823j-5qj8
Mar 06, 2025
Out-of-bounds Write in SixLabors ImageSharp
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/issues/2859 https://github.com/SixLabors/ImageSharp/issues/2890 Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
1.0.0
1.0.0-beta0001
+ 24 more Show less
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.10
3.1.7
References Updated Mar 07, 2025 · Source: OSV.dev
CVE-2024-41132
GHSA-qxrv-gp6x-rc23
Jul 22, 2024
SixLabors ImageSharp has Excessive Memory Allocation in Gif Decoder
Medium
Network
Low
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. PatchesHas the problem been patched? What versions should users upgrade to? The problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Before calling ReferencesAre there any links users can visit to find out more?
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41131
GHSA-63p8-c4ww-9cg7
Jul 22, 2024
SixLabors ImageSharp Out-of-bounds Write
High
Network
Low
None
None
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/pull/2754 https://github.com/SixLabors/ImageSharp/pull/2756 Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32036
GHSA-5x7m-6737-26cr
Apr 15, 2024
SixLabors.ImageSharp vulnerable to data leakage
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
High
None
None
ImpactA data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the resulting image buffer. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsNone ReferencesNone Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32035
GHSA-g85r-6x2q-45w7
Apr 15, 2024
SixLabors.ImageSharp vulnerable to Memory Allocation with Excessive Size Value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in image decoders. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. This flaw can be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on ImageSharp for image processing tasks. Users and administrators are advised to update to the latest version of ImageSharp that addresses this vulnerability to mitigate the risk of exploitation. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsBefore calling References
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27929
GHSA-65x7-c272-7g7r
Mar 05, 2024
Use After Free in SixLabors.ImageSharp
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
ImpactA heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when an attacker passes a specially crafted PNG image file to ImageSharp for conversion, potentially leading to information disclosure. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.3 or v2.1.7. WorkaroundsNone ReferencesNone Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
+ 17 more Show less
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
3.1.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.0.2
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.0.1
patch
7 CVEs
CVE-2025-54575
GHSA-rxmq-m78w-7wmc
Jul 30, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.11 or v2.1.11. WorkaroundsNone. Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 29 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.10
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
2.1.11
3.1.11
References
Updated Jul 31, 2025 · Source: OSV.dev
CVE-2025-27598
GHSA-2cmq-823j-5qj8
Mar 06, 2025
Out-of-bounds Write in SixLabors ImageSharp
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/issues/2859 https://github.com/SixLabors/ImageSharp/issues/2890 Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
1.0.0
1.0.0-beta0001
+ 24 more Show less
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.10
3.1.7
References Updated Mar 07, 2025 · Source: OSV.dev
CVE-2024-41132
GHSA-qxrv-gp6x-rc23
Jul 22, 2024
SixLabors ImageSharp has Excessive Memory Allocation in Gif Decoder
Medium
Network
Low
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. PatchesHas the problem been patched? What versions should users upgrade to? The problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Before calling ReferencesAre there any links users can visit to find out more?
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41131
GHSA-63p8-c4ww-9cg7
Jul 22, 2024
SixLabors ImageSharp Out-of-bounds Write
High
Network
Low
None
None
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/pull/2754 https://github.com/SixLabors/ImageSharp/pull/2756 Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32036
GHSA-5x7m-6737-26cr
Apr 15, 2024
SixLabors.ImageSharp vulnerable to data leakage
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
High
None
None
ImpactA data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the resulting image buffer. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsNone ReferencesNone Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32035
GHSA-g85r-6x2q-45w7
Apr 15, 2024
SixLabors.ImageSharp vulnerable to Memory Allocation with Excessive Size Value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in image decoders. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. This flaw can be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on ImageSharp for image processing tasks. Users and administrators are advised to update to the latest version of ImageSharp that addresses this vulnerability to mitigate the risk of exploitation. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsBefore calling References
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27929
GHSA-65x7-c272-7g7r
Mar 05, 2024
Use After Free in SixLabors.ImageSharp
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
ImpactA heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when an attacker passes a specially crafted PNG image file to ImageSharp for conversion, potentially leading to information disclosure. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.3 or v2.1.7. WorkaroundsNone ReferencesNone Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
+ 17 more Show less
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
3.1.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.0.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.0.0
initial
7 CVEs
CVE-2025-54575
GHSA-rxmq-m78w-7wmc
Jul 30, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.11 or v2.1.11. WorkaroundsNone. Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 29 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.10
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.10
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
2.1.11
3.1.11
References
Updated Jul 31, 2025 · Source: OSV.dev
CVE-2025-27598
GHSA-2cmq-823j-5qj8
Mar 06, 2025
Out-of-bounds Write in SixLabors ImageSharp
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/issues/2859 https://github.com/SixLabors/ImageSharp/issues/2890 Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
1.0.0
1.0.0-beta0001
+ 24 more Show less
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.10
3.1.7
References Updated Mar 07, 2025 · Source: OSV.dev
CVE-2024-41132
GHSA-qxrv-gp6x-rc23
Jul 22, 2024
SixLabors ImageSharp has Excessive Memory Allocation in Gif Decoder
Medium
Network
Low
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. PatchesHas the problem been patched? What versions should users upgrade to? The problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? Before calling ReferencesAre there any links users can visit to find out more?
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41131
GHSA-63p8-c4ww-9cg7
Jul 22, 2024
SixLabors ImageSharp Out-of-bounds Write
High
Network
Low
None
None
ImpactAn Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9. WorkaroundsNone. Referenceshttps://github.com/SixLabors/ImageSharp/pull/2754 https://github.com/SixLabors/ImageSharp/pull/2756 Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 21 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
Fixed in
2.1.9
3.1.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32036
GHSA-5x7m-6737-26cr
Apr 15, 2024
SixLabors.ImageSharp vulnerable to data leakage
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
High
None
None
ImpactA data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the resulting image buffer. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsNone ReferencesNone Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32035
GHSA-g85r-6x2q-45w7
Apr 15, 2024
SixLabors.ImageSharp vulnerable to Memory Allocation with Excessive Size Value
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in image decoders. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. This flaw can be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on ImageSharp for image processing tasks. Users and administrators are advised to update to the latest version of ImageSharp that addresses this vulnerability to mitigate the risk of exploitation. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8. WorkaroundsBefore calling References
Affected versions
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
+ 19 more Show less
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
Fixed in
2.1.8
3.1.4
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27929
GHSA-65x7-c272-7g7r
Mar 05, 2024
Use After Free in SixLabors.ImageSharp
7.1
/ 10
High
Local
Low
None
Required
Unchanged
High
None
High
ImpactA heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when an attacker passes a specially crafted PNG image file to ImageSharp for conversion, potentially leading to information disclosure. PatchesThe problem has been patched. All users are advised to upgrade to v3.1.3 or v2.1.7. WorkaroundsNone ReferencesNone Affected versions
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
1.0.0
1.0.0-beta0001
1.0.0-beta0002
1.0.0-beta0003
1.0.0-beta0004
1.0.0-beta0005
+ 17 more Show less
1.0.0-beta0006
1.0.0-beta0007
1.0.0-rc0001
1.0.0-rc0002
1.0.0-rc0003
1.0.1
1.0.2
1.0.3
1.0.4
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
3.1.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.0.0
initial
Dependencies (9)
+ 1 more
Changelog
|