CVE-2024-32036
ImageSharp is a 2D graphics API. A data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the resulting image buffer. The problem has been patched in v3.1.4 and v2.1.8.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS probability
- 0.57%
- CWE
- CWE-226
- Published
- 2024-04-15
- Last modified
- 2026-03-13
Affected products
- SixLabors ImageSharp
- SixLabors ImageSharp
Weakness type
Related vulnerabilities
- CVE-2026-18023 — Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a...
- CVE-2026-74791 — Scriban before 7.0.0 Authorization Bypass via Stale Include Cache
- CVE-2026-74250 — In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning...
- CVE-2026-47247 — libheif Vulnerable to Heap Information Disclosure via Grid Image Gap + Uninitialized Pixel Plane Allocation
- CVE-2026-13585 — Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not...
- CVE-2026-48984 — pam_usb: xfree() does not call explicit_bzero — sensitive cryptographic material may linger in freed heap
- CVE-2026-32960 — SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a sensitive...
- CVE-2026-5795 — In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two...