Disclosure summary
### Summary `SixLabors.ImageSharp` can terminate a process when an application decodes an attacker-supplied 32-bit floating-point TIFF as `Image` and applies `HistogramEqualization()`. An IEEE positive-infinity TIFF sample reaches a non-finite or otherwise out-of-range `HalfVector4` component, depending on the release. The histogram equalization path derives a luminance-based histogram index without validating that result, reaching an unsafe out-of-range access. This report covers `HistogramEqualization` only. It does not claim Adaptive Histogram Equalization or AutoLevel behavior. ### Affected package and versions - Package: `SixLabors.ImageSharp` (NuGet) - Affected range: `>= 2.0.0, x.HistogramEqualization()); Console.Error.WriteLine("completed"); } } ``` Project file: ```xml Exe net8.0 enable enable /root/.nuget/packages/sixlabors.imagesharp/4.1.1/lib/net8.0/SixLabors.ImageSharp.dll /root/.nuget/packages/system.io.hashing/8.0.0/lib/net8.0/System.IO.Hashing.dll ``` Dockerfile: ```dockerfile FROM mcr.microsoft.com/dotnet/sdk:8.0 WORKDIR /work COPY j3p4.csproj Program.cs ./ RUN printf '%s\n' 'net8.0' > fetch.csproj \ && dotnet restore fetch.csproj --nologo \ && rm fetch.csproj \ &&
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-j3p4-wp97-rph4
Open original source · Updated Oct 07, 2026
ImageSharp: HistogramEqualization uses an unvalidated luminance as an unchecked histogram index
Source severity: HIGH / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| nuget | SixLabors.ImageSharp | >= 2.0.0, | 4.1.2 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-07T16:24:23-04:00
MODIFIED 2026-10-07T16:24:24-04:00
INGESTED 2026-10-08T12:30:39-04:00