CVE detail
CVE-2024-27929 — CVE-2024-27929
Published 2024-03-05 · Modified 2026-06-17 · Vendor sixlabors · Product imagesharp · Source nvd
HIGH
severity
CVSS-derived band
0.0035
EPSS probability
exploitation probability, 30d
28.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
ImageSharp is a managed, cross-platform, 2D graphics library. A heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when an attacker passes a specially crafted PNG image file to ImageSharp for conversion, potentially leading to information disclosure. This issue has been patched in versions 3.1.3 and 2.1.7.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References