- 
                Notifications
    
You must be signed in to change notification settings  - Fork 1
 
Description
π Vulnerable Library - TestSuite.Shared-1.0.0
Path to dependency file: /tools/TestSuite/TestSuite.ApiTests/TestSuite.ApiTests.csproj
Findings
| Finding | Severity | π― CVSS | Exploit Maturity | EPSS | Library | Type | Fixed in | Remediation Available | Reachability | 
|---|---|---|---|---|---|---|---|---|---|
| CVE-2025-54575 | π Medium | 6.9 | Not Defined | < 1% | sixlabors.imagesharp.3.1.5.nupkg | Transitive | N/A | β | 
Details
π CVE-2025-54575
Vulnerable Library - sixlabors.imagesharp.3.1.5.nupkg
A new, fully featured, fully managed, cross-platform, 2D graphics API for .NET
Library home page: https://api.nuget.org/packages/sixlabors.imagesharp.3.1.5.nupkg
Path to dependency file: /tools/TestSuite/TestSuite.Shared/TestSuite.Shared.csproj
Path to vulnerable library: /home/wss-scanner/.nuget/packages/sixlabors.imagesharp/3.1.5/sixlabors.imagesharp.3.1.5.nupkg
Dependency Hierarchy:
- 
squidex.assets.6.19.0.nupkg (Root Library)
- β sixlabors.imagesharp.3.1.5.nupkg (Vulnerable Library)
 
 - 
squidex.assets.imagesharp.6.22.0.nupkg (Root Library)
- β sixlabors.imagesharp.3.1.5.nupkg (Vulnerable Library)
 
 - 
squidex.assets.imagesharp.6.19.0.nupkg (Root Library)
- squidex.assets.6.19.0.nupkg
- β sixlabors.imagesharp.3.1.5.nupkg (Vulnerable Library)
 
 
 - squidex.assets.6.19.0.nupkg
 - 
TestSuite.Shared-1.0.0 (Root Library)
- squidex.assets.6.19.0.nupkg
- β sixlabors.imagesharp.3.1.5.nupkg (Vulnerable Library)
 
 
 - squidex.assets.6.19.0.nupkg
 
Vulnerability Details
ImageSharp is a 2D graphics library. In versions below 2.1.11 and 3.0.0 through 3.1.10, a specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial of service. Applications processing untrusted GIF input should upgrade to a patched version. This issue is fixed in versions 2.1.11 and 3.1.11.
Publish Date: Jul 30, 2025 07:55 PM
URL: CVE-2025-54575
Threat Assessment
Exploit Maturity:Not Defined
EPSS:< 1%
Score: 6.9
Suggested Fix
Type: Upgrade version
Origin:
Release Date:
Fix Resolution :