CVE-2025-27598

I

mageSharp is a 2D graphics API. An Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. The problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sixlabors:imagesharp:*:*:*:*:*:*:*:*
cpe:2.3:a:sixlabors:imagesharp:*:*:*:*:*:*:*:*

History

24 Mar 2025, 18:36

Type Values Removed Values Added
First Time Sixlabors
Sixlabors imagesharp
CPE cpe:2.3:a:sixlabors:imagesharp:*:*:*:*:*:*:*:*
References () https://github.com/SixLabors/ImageSharp/issues/2859 - () https://github.com/SixLabors/ImageSharp/issues/2859 - Exploit, Issue Tracking
References () https://github.com/SixLabors/ImageSharp/pull/2890 - () https://github.com/SixLabors/ImageSharp/pull/2890 - Issue Tracking, Patch
References () https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-2cmq-823j-5qj8 - () https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-2cmq-823j-5qj8 - Vendor Advisory

07 Mar 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-06 23:15

Updated : 2025-03-24 18:36


NVD link : CVE-2025-27598

Mitre link : CVE-2025-27598

CVE.ORG link : CVE-2025-27598


JSON object : View

Products Affected
CWE
CWE-787

Out-of-bounds Write