Open Closed

Urgent: Security vulnerabilities in SixLabors.ImageSharp 3.1.11 used by Volo.Abp.Imaging.ImageSharp #10910


User avatar
0
ahmet.kuyrukcu created

Summary

On 2026-10-07, five security advisories (three of them high severity) were published for SixLabors.ImageSharp. ABP depends on the affected version through the following chain:

Advisories

| Advisory | Severity | Affected range | Patched | |---|---|---|---| | GHSA-j3p4-wp97-rph4 | High | >= 2.0.0, <= 4.1.1 | 4.1.2 | | GHSA-j9gm-c75j-xc9q | High | >= 2.0.0, <= 4.1.1 | 4.1.2 | | GHSA-jjfr-hcj7-qf5w | High | >= 2.1.0, <= 4.1.1 | 4.1.2 | | GHSA-gwg2-r3hj-4w44 | Moderate | >= 1.0.0-beta0001, <= 4.1.1 | 4.1.2 | | GHSA-wmxv-xphr-5c9g | Moderate | >= 2.0.0, <= 4.1.1 | 4.1.2 |

There is no patched 3.1.x release; the only fixed version is 4.1.2.

Request

Please treat this as urgent and let us know:

  1. When a patched ABP release that resolves these advisories will be available.

Thank you.

Markdown supported.
Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post)

2 Answer(s)
  • User Avatar
    0
    AI-Bot created
    Support Team ABP Agent

    1. Solution

    • ABP does not publish ETAs or release dates for dependency/security upgrades via public support answers. For an “urgent / when will it be released?” request, the only official channel to get a committed timeline is Volosoft support: contact via the ABP contact page below.

    • What you can do immediately (safe workaround in your app): override the transitive dependency and force a patched ImageSharp version in your own solution until ABP updates Volo.Abp.Imaging.ImageSharp.

      • Add an explicit top-level package reference to SixLabors.ImageSharp 4.1.2 (the first fixed version per your table) in the projects that end up using it (typically your *.HttpApi.Host and/or *.Web / *.Web.Public, depending on where image operations run).
      • Example:
    <ItemGroup>
          <PackageReference Include="SixLabors.ImageSharp" Version="4.1.2" />
        </ItemGroup>
    
    • Then run a restore and verify the resolved graph (e.g., dotnet list package --include-transitive) to confirm SixLabors.ImageSharp resolves to 4.1.2 instead of 3.1.11.

    • If you want to avoid ImageSharp entirely until an ABP package update is published, ABP already provides an alternative imaging provider: Volo.Abp.Imaging.MagickNet (swap the provider package and configuration in your solution accordingly).

    • For a definitive answer to “when will ABP ship a fix?”, please contact Volosoft directly:

      • https://abp.io/contact

    2. Sources

    • https://abp.io/community/articles/f93ab2bc
    • https://abp.io/contact

    This response was generated by AI. If it didn’t solve your problem, feel free to post a new answer — our support team will jump in to help you soon.

    Markdown supported.
    Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post)
  • User Avatar
    0
    maliming created
    Support Team Fullstack Developer

    Hi,

    Starting with 10.4.0, Volo.Abp.Account.Pro.Public.Application uses Volo.Abp.Imaging.SkiaSharp instead of Volo.Abp.Imaging.ImageSharp. So upgrading to 10.4.0 or later (10.7.0 is the latest stable) removes the ImageSharp dependency that comes from Account Pro. After the upgrade, run dotnet list package --include-transitive for your solution (including the AuthServer and HttpApi.Host projects) to make sure nothing else still pulls in SixLabors.ImageSharp.

    If you need to stay on 10.3.0 for now, you can add a direct reference to the patched version:

    <PackageReference Include="SixLabors.ImageSharp" Version="4.1.2" />
    

    Add it to every project where dotnet list package --include-transitive shows SixLabors.ImageSharp, then run the command again to make sure it resolves to 4.1.2.

    Note that ImageSharp 4.1.2 checks for a Six Labors license at build time. Without one, Debug builds show a warning and Release builds fail. You can set the license with the SixLaborsLicenseKey / SixLaborsLicenseFile MSBuild properties or by adding a sixlabors.lic file. See https://sixlabors.com/pricing/

    Also, in 10.3.0 Account Pro only calls ImageSharp when AbpProfilePictureOptions.EnableImageCompression is enabled, and it's off by default. If you enabled it, test profile picture upload after the change and check the server logs for compression errors.

    Thanks

    Markdown supported.
    Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post)
Boost Your Development
ABP Live Training
Packages
See Trainings
Mastering ABP Framework Book
The Official Guide
Mastering
ABP Framework
Learn More
Mastering ABP Framework Book
Made with ❤️ on ABP v10.8.0-preview. Updated on October 08, 2026, 12:23
1
ABP Assistant
🔐 You need to be logged in to use the chatbot. Please log in first.