SixLabors.Fonts is vulnerable to Denial of Service (DoS)
41
Medium Risk
SixLabors.Fonts flattens COLR v1 color-glyph paint graphs by walking paint nodes recursively without tracking already-visited nodes or bounding nesting depth and edge count. A malformed font whose paint graph contains cycles or deep nesting drives unbounded recursion into stack exhaustion, while a highly branching graph fans out into unbounded work. Resolving color glyphs from such a font crashes or hangs the calling process. The fix adds active-path cycle tracking, a maximum nesting depth and edge budget, and safe empty-paint fallbacks.
You are affected if you are using a version that falls within the vulnerable range and you process untrusted or externally supplied fonts that contain COLR v1 color-glyph tables.
SixLabors.Fonts is vulnerable to Denial of Service (DoS) in versions 3.1.0 - 3.1.0.
Upgrade the SixLabors.Fonts library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.