Disclosure summary
### Summary The TIFF CCITT Group 4 (T6) encoder writes beyond its logical compressed-data buffer when encoding a 1-bit image. A valid 1×1 Group 4 TIFF decoded and re-encoded with the default `TiffEncoder` terminates the process with an unhandled exception. ### Affected package and versions - Package: `SixLabors.ImageSharp` (NuGet) - Affected range: `>= 2.1.0,
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-jjfr-hcj7-qf5w
Open original source · Updated Oct 07, 2026
ImageSharp: TIFF CCITT T6 encoder writes beyond an undersized output buffer
Source severity: HIGH / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| nuget | SixLabors.ImageSharp | >= 2.1.0, | 4.1.2 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-07T16:24:46-04:00
MODIFIED 2026-10-07T16:24:49-04:00
INGESTED 2026-10-08T12:30:39-04:00