Skip to content

PdfSharpCore has an implicitly referenced package (SixLabors.ImageSharp) which has five CVEsΒ #462

Open
@cyclorama

Description

I currently have PdfSharpCore version 1.3.65, and Docker Scout is detecting two CVEs relating to a transitively referenced package ImageSharp version 1.0.4.0.

The CVEs: CVE-2024-27929, CVE-2024-41131, CVE-2024-32035, CVE-2024-32036, CVE-2024-41132

I am unable to explicitly install the updated ImageSharp package due to the commercial licence it has, however transitive references are allowed according to ImageSharp's licence.

Can you please update the ImageSharp dependency to the latest version?

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions