Summary
On 2026-10-07, five security advisories (three of them high severity) were published for SixLabors.ImageSharp. ABP depends on the affected version through the following chain:
Advisories
| Advisory | Severity | Affected range | Patched | |---|---|---|---| | GHSA-j3p4-wp97-rph4 | High | >= 2.0.0, <= 4.1.1 | 4.1.2 | | GHSA-j9gm-c75j-xc9q | High | >= 2.0.0, <= 4.1.1 | 4.1.2 | | GHSA-jjfr-hcj7-qf5w | High | >= 2.1.0, <= 4.1.1 | 4.1.2 | | GHSA-gwg2-r3hj-4w44 | Moderate | >= 1.0.0-beta0001, <= 4.1.1 | 4.1.2 | | GHSA-wmxv-xphr-5c9g | Moderate | >= 2.0.0, <= 4.1.1 | 4.1.2 |
There is no patched 3.1.x release; the only fixed version is 4.1.2.
Request
Please treat this as urgent and let us know:
- When a patched ABP release that resolves these advisories will be available.
Thank you.
2 Answer(s)
-
0
1. Solution
ABP does not publish ETAs or release dates for dependency/security upgrades via public support answers. For an “urgent / when will it be released?” request, the only official channel to get a committed timeline is Volosoft support: contact via the ABP contact page below.
What you can do immediately (safe workaround in your app): override the transitive dependency and force a patched ImageSharp version in your own solution until ABP updates
Volo.Abp.Imaging.ImageSharp.- Add an explicit top-level package reference to SixLabors.ImageSharp 4.1.2 (the first fixed version per your table) in the projects that end up using it (typically your
*.HttpApi.Hostand/or*.Web/*.Web.Public, depending on where image operations run). - Example:
- Add an explicit top-level package reference to SixLabors.ImageSharp 4.1.2 (the first fixed version per your table) in the projects that end up using it (typically your
<ItemGroup> <PackageReference Include="SixLabors.ImageSharp" Version="4.1.2" /> </ItemGroup>Then run a restore and verify the resolved graph (e.g.,
dotnet list package --include-transitive) to confirmSixLabors.ImageSharpresolves to 4.1.2 instead of3.1.11.If you want to avoid ImageSharp entirely until an ABP package update is published, ABP already provides an alternative imaging provider:
Volo.Abp.Imaging.MagickNet(swap the provider package and configuration in your solution accordingly).For a definitive answer to “when will ABP ship a fix?”, please contact Volosoft directly:
- https://abp.io/contact
2. Sources
- https://abp.io/community/articles/f93ab2bc
- https://abp.io/contact
This response was generated by AI. If it didn’t solve your problem, feel free to post a new answer — our support team will jump in to help you soon.
Markdown supported.Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post) -
0
Hi,
Starting with 10.4.0,
Volo.Abp.Account.Pro.Public.ApplicationusesVolo.Abp.Imaging.SkiaSharpinstead ofVolo.Abp.Imaging.ImageSharp. So upgrading to 10.4.0 or later (10.7.0 is the latest stable) removes the ImageSharp dependency that comes from Account Pro. After the upgrade, rundotnet list package --include-transitivefor your solution (including the AuthServer and HttpApi.Host projects) to make sure nothing else still pulls inSixLabors.ImageSharp.If you need to stay on 10.3.0 for now, you can add a direct reference to the patched version:
<PackageReference Include="SixLabors.ImageSharp" Version="4.1.2" />Add it to every project where
dotnet list package --include-transitiveshowsSixLabors.ImageSharp, then run the command again to make sure it resolves to 4.1.2.Note that ImageSharp 4.1.2 checks for a Six Labors license at build time. Without one, Debug builds show a warning and Release builds fail. You can set the license with the
SixLaborsLicenseKey/SixLaborsLicenseFileMSBuild properties or by adding asixlabors.licfile. See https://sixlabors.com/pricing/Also, in 10.3.0 Account Pro only calls ImageSharp when
AbpProfilePictureOptions.EnableImageCompressionis enabled, and it's off by default. If you enabled it, test profile picture upload after the change and check the server logs for compression errors.Thanks
Markdown supported.Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post)