Sixlabors develops ImageSharp, a widely embedded open-source image-processing library for the .NET ecosystem. The vendor's vulnerability profile centers on resource-handling and memory-management weaknesses, including unbounded allocation, excessive-size allocations, out-of-bounds writes, and improper handling of sensitive data, which reflect the parsing and transformation demands of an image-manipulation codebase. Defenders should prioritize inventory of downstream applications that depend on this library, since remediation typically requires rebuilds at the consuming-application layer; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sixlabors over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-41132HIGH ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif | Jul 22, 2024 | 7.5 | 23 | NO | NO |
CVE-2025-27598HIGH ImageSharp is a 2D graphics API. An Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gi | Mar 6, 2025 | 7.5 | 22 | NO | NO |
CVE-2024-41131HIGH ImageSharp is a 2D graphics API. An Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gi | Jul 22, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-27929HIGH ImageSharp is a managed, cross-platform, 2D graphics library. A heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulner | Mar 5, 2024 | 7.1 | 20 | NO | NO |
CVE-2024-32036MEDIUM ImageSharp is a 2D graphics API. A data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JP | Apr 15, 2024 | 6.5 | 19 | NO | NO |
CVE-2024-32035MEDIUM ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in image d | Apr 15, 2024 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sixlabors.
Media articles that mention a CVE ID that affects a product developed by Sixlabors — matched by CVE ID, not by vendor name.