Security Notice: SixLabors.ImageSharp Vulnerabilities
Last updated: 09 October 2026, 09:50 UTC
Summary
Security scanners are flagging vulnerabilities in SixLabors.ImageSharp, an image library that some Iron Software products depend on. We've confirmed that IronPDF is affected, and we're checking our other products now. This is our engineering team's top priority. Our next status update will be published by 13 October 2026.
What we're doing
- Our engineers are working on a fix and testing the changes.
- We'll update this page as our investigation continues.
Timeline
Our next status update will be published by 13 October 2026. It will include the results of our investigation into our other products.
What you can do now
- Don't roll back to an earlier version. Earlier versions carry the same advisories.
- Don't force a newer ImageSharp version into your project. It can cause API conflicts and build errors.
- If your security policy allows it, you can temporarily suppress the advisories until a fix is available.
Frequently asked questions
Is my product affected?
We've confirmed that IronPDF is affected, and we're checking our other products now. We'll update this page as our investigation continues.
When will a fix be available?
We can't confirm a date yet. Our next status update will be published by 13 October 2026.
Will you notify me when it's fixed?
Yes. If you've contacted us about this issue, we'll reach out to you when the fix is released. You can also check this page, which we'll keep up to date.
Advisory references
GHSA-j3p4-wp97-rph4, GHSA-j9gm-c75j-xc9q and GHSA-jjfr-hcj7-qf5w (high), and GHSA-gwg2-r3hj-4w44 and GHSA-wmxv-xphr-5c9g (moderate).
Getting help
Contact [support@ironsoftware.com]. Include your product, version and target framework, and the advisory IDs your scanner reports.