Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, ExifReader.ReadValues64 trusts the 64-bit BigTIFF IFD entry count and iterates once per declared entry. When fewer than 20 bytes remain, ExifReader.ReadValue64 returns without advancing the stream or terminating the outer loop, so a small malformed BigTIFF can keep one decoder thread executing for an attacker-controlled duration. This report does not claim worker-pool exhaustion. This issue is fixed in version 4.1.2. | |
| Title | ImageSharp: BigTIFF IFD count can keep a decoder thread in a non-progressing loop | |
| Weaknesses | CWE-835 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-06T18:21:55.088Z
Reserved: 2026-10-06T15:33:55.333Z
Link: CVE-2026-106116
Updated: 2026-10-06T18:21:10.476Z
Status : Received
Published: 2026-10-06T18:16:53.400
Modified: 2026-10-06T19:17:42.387
Link: CVE-2026-106116
No data.
OpenCVE Enrichment
No data.
-
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')