golang.org/x/image
Activity
- Latest release
- 5d ago
- Total releases
- 21
- Cadence
- ~28 days
- Last 12 months
- 15
Details
- First release
- Apr 06, 2025
| Version | Released | |
|---|---|---|
v0.46.0
minor
|
v0.46.0
minor
Dependencies (2)
|
|
v0.45.0
minor
|
v0.45.0
minor
Dependencies (2)
|
|
v0.44.0
minor
1 CVE
CVE-2026-46603
GO-2026-6222
Aug 14, 2026
Excessive memory allocation during VP8L decoding in golang.org/x/image VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion. Fixed in
0.45.0
Updated Aug 15, 2026 · Source: OSV.dev |
v0.44.0
minor
Dependencies (1)
|
|
v0.43.0
minor
1 CVE
CVE-2026-46603
GO-2026-6222
Aug 14, 2026
Excessive memory allocation during VP8L decoding in golang.org/x/image VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion. Fixed in
0.45.0
Updated Aug 15, 2026 · Source: OSV.dev |
v0.43.0
minor
Dependencies (1)
|
|
v0.42.0
minor
4 CVEs
CVE-2026-46603
GO-2026-6222
Aug 14, 2026
Excessive memory allocation during VP8L decoding in golang.org/x/image VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion. Fixed in
0.45.0
Updated Aug 15, 2026 · Source: OSV.dev
CVE-2026-46604
GO-2026-5066
Jun 26, 2026
Panic decoding image with out-of-bounds strip offset in x/image/tiff in golang.org/x/image The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset. Fixed in
0.43.0
Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-46602
GO-2026-5062
Jun 18, 2026
Lack of limit on tile sizes in x/image/tiff in golang.org/x/image The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-46601
GO-2026-5061
Jun 18, 2026
Panic on VP8 alpha channel size mismatch in x/image/webp in golang.org/x/image The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev |
v0.42.0
minor
Dependencies (1)
|
|
v0.41.0
minor
5 CVEs
CVE-2026-46603
GO-2026-6222
Aug 14, 2026
Excessive memory allocation during VP8L decoding in golang.org/x/image VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion. Fixed in
0.45.0
Updated Aug 15, 2026 · Source: OSV.dev
CVE-2026-46604
GO-2026-5066
Jun 26, 2026
Panic decoding image with out-of-bounds strip offset in x/image/tiff in golang.org/x/image The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset. Fixed in
0.43.0
Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-46602
GO-2026-5062
Jun 18, 2026
Lack of limit on tile sizes in x/image/tiff in golang.org/x/image The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-46601
GO-2026-5061
Jun 18, 2026
Panic on VP8 alpha channel size mismatch in x/image/webp in golang.org/x/image The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-33813
GO-2026-4961
Apr 21, 2026
Panic when decoding large WEBP image on 32-bit platforms in golang.org/x/image Parsing a WEBP image with an invalid, large size panics on 32-bit platforms. Fixed in
0.42.0
Updated Jun 25, 2026 · Source: OSV.dev |
v0.41.0
minor
Dependencies (1)
|
|
v0.40.0
minor
7 CVEs
CVE-2026-46603
GO-2026-6222
Aug 14, 2026
Excessive memory allocation during VP8L decoding in golang.org/x/image VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion. Fixed in
0.45.0
Updated Aug 15, 2026 · Source: OSV.dev
CVE-2026-46599
GHSA-q675-qj96-32m9
GO-2026-5032
Jul 02, 2026
golang.org/x/image/tiff has excessive resource consumption in PackBits decompression
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data. Fixed in
0.41.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46604
GO-2026-5066
Jun 26, 2026
Panic decoding image with out-of-bounds strip offset in x/image/tiff in golang.org/x/image The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset. Fixed in
0.43.0
Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-46602
GO-2026-5062
Jun 18, 2026
Lack of limit on tile sizes in x/image/tiff in golang.org/x/image The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-46601
GO-2026-5061
Jun 18, 2026
Panic on VP8 alpha channel size mismatch in x/image/webp in golang.org/x/image The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-42500
GO-2026-5031
May 29, 2026
Panic when reading out of bound palette index in golang.org/x/image/bmp Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image. Fixed in
0.41.0
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-33813
GO-2026-4961
Apr 21, 2026
Panic when decoding large WEBP image on 32-bit platforms in golang.org/x/image Parsing a WEBP image with an invalid, large size panics on 32-bit platforms. Fixed in
0.42.0
Updated Jun 25, 2026 · Source: OSV.dev |
v0.40.0
minor
Dependencies (1)
|
|
v0.39.0
minor
7 CVEs
CVE-2026-46603
GO-2026-6222
Aug 14, 2026
Excessive memory allocation during VP8L decoding in golang.org/x/image VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion. Fixed in
0.45.0
Updated Aug 15, 2026 · Source: OSV.dev
CVE-2026-46599
GHSA-q675-qj96-32m9
GO-2026-5032
Jul 02, 2026
golang.org/x/image/tiff has excessive resource consumption in PackBits decompression
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data. Fixed in
0.41.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46604
GO-2026-5066
Jun 26, 2026
Panic decoding image with out-of-bounds strip offset in x/image/tiff in golang.org/x/image The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset. Fixed in
0.43.0
Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-46602
GO-2026-5062
Jun 18, 2026
Lack of limit on tile sizes in x/image/tiff in golang.org/x/image The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-46601
GO-2026-5061
Jun 18, 2026
Panic on VP8 alpha channel size mismatch in x/image/webp in golang.org/x/image The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-42500
GO-2026-5031
May 29, 2026
Panic when reading out of bound palette index in golang.org/x/image/bmp Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image. Fixed in
0.41.0
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-33813
GO-2026-4961
Apr 21, 2026
Panic when decoding large WEBP image on 32-bit platforms in golang.org/x/image Parsing a WEBP image with an invalid, large size panics on 32-bit platforms. Fixed in
0.42.0
Updated Jun 25, 2026 · Source: OSV.dev |
v0.39.0
minor
Dependencies (1)
|
|
v0.38.0
minor
8 CVEs
CVE-2026-46603
GO-2026-6222
Aug 14, 2026
Excessive memory allocation during VP8L decoding in golang.org/x/image VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion. Fixed in
0.45.0
Updated Aug 15, 2026 · Source: OSV.dev
CVE-2026-46599
GHSA-q675-qj96-32m9
GO-2026-5032
Jul 02, 2026
golang.org/x/image/tiff has excessive resource consumption in PackBits decompression
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data. Fixed in
0.41.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46604
GO-2026-5066
Jun 26, 2026
Panic decoding image with out-of-bounds strip offset in x/image/tiff in golang.org/x/image The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset. Fixed in
0.43.0
Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-46602
GO-2026-5062
Jun 18, 2026
Lack of limit on tile sizes in x/image/tiff in golang.org/x/image The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-46601
GO-2026-5061
Jun 18, 2026
Panic on VP8 alpha channel size mismatch in x/image/webp in golang.org/x/image The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-42500
GO-2026-5031
May 29, 2026
Panic when reading out of bound palette index in golang.org/x/image/bmp Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image. Fixed in
0.41.0
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-33812
GO-2026-4962
Apr 21, 2026
Excessive memory allocation when decoding malicious SFNT in golang.org/x/image Parsing a malicious font file can cause excessive memory allocation. Fixed in
0.39.0
Updated May 14, 2026 · Source: OSV.dev
CVE-2026-33813
GO-2026-4961
Apr 21, 2026
Panic when decoding large WEBP image on 32-bit platforms in golang.org/x/image Parsing a WEBP image with an invalid, large size panics on 32-bit platforms. Fixed in
0.42.0
Updated Jun 25, 2026 · Source: OSV.dev |
v0.38.0
minor
Dependencies (1)
|
|
v0.37.0
minor
9 CVEs
CVE-2026-46603
GO-2026-6222
Aug 14, 2026
Excessive memory allocation during VP8L decoding in golang.org/x/image VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion. Fixed in
0.45.0
Updated Aug 15, 2026 · Source: OSV.dev
CVE-2026-46599
GHSA-q675-qj96-32m9
GO-2026-5032
Jul 02, 2026
golang.org/x/image/tiff has excessive resource consumption in PackBits decompression
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data. Fixed in
0.41.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46604
GO-2026-5066
Jun 26, 2026
Panic decoding image with out-of-bounds strip offset in x/image/tiff in golang.org/x/image The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset. Fixed in
0.43.0
Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-46602
GO-2026-5062
Jun 18, 2026
Lack of limit on tile sizes in x/image/tiff in golang.org/x/image The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-46601
GO-2026-5061
Jun 18, 2026
Panic on VP8 alpha channel size mismatch in x/image/webp in golang.org/x/image The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-42500
GO-2026-5031
May 29, 2026
Panic when reading out of bound palette index in golang.org/x/image/bmp Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image. Fixed in
0.41.0
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-33812
GO-2026-4962
Apr 21, 2026
Excessive memory allocation when decoding malicious SFNT in golang.org/x/image Parsing a malicious font file can cause excessive memory allocation. Fixed in
0.39.0
Updated May 14, 2026 · Source: OSV.dev
CVE-2026-33813
GO-2026-4961
Apr 21, 2026
Panic when decoding large WEBP image on 32-bit platforms in golang.org/x/image Parsing a WEBP image with an invalid, large size panics on 32-bit platforms. Fixed in
0.42.0
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33809
GHSA-44p7-9xx4-hf2g
GO-2026-4815
Mar 25, 2026
Go Images vulnerable to an out-of-memory error via a crafted TIFF file
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error. Fixed in
0.38.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.37.0
minor
Dependencies (1)
|
|
v0.36.0
minor
9 CVEs
CVE-2026-46603
GO-2026-6222
Aug 14, 2026
Excessive memory allocation during VP8L decoding in golang.org/x/image VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion. Fixed in
0.45.0
Updated Aug 15, 2026 · Source: OSV.dev
CVE-2026-46599
GHSA-q675-qj96-32m9
GO-2026-5032
Jul 02, 2026
golang.org/x/image/tiff has excessive resource consumption in PackBits decompression
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data. Fixed in
0.41.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46604
GO-2026-5066
Jun 26, 2026
Panic decoding image with out-of-bounds strip offset in x/image/tiff in golang.org/x/image The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset. Fixed in
0.43.0
Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-46602
GO-2026-5062
Jun 18, 2026
Lack of limit on tile sizes in x/image/tiff in golang.org/x/image The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-46601
GO-2026-5061
Jun 18, 2026
Panic on VP8 alpha channel size mismatch in x/image/webp in golang.org/x/image The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-42500
GO-2026-5031
May 29, 2026
Panic when reading out of bound palette index in golang.org/x/image/bmp Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image. Fixed in
0.41.0
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-33812
GO-2026-4962
Apr 21, 2026
Excessive memory allocation when decoding malicious SFNT in golang.org/x/image Parsing a malicious font file can cause excessive memory allocation. Fixed in
0.39.0
Updated May 14, 2026 · Source: OSV.dev
CVE-2026-33813
GO-2026-4961
Apr 21, 2026
Panic when decoding large WEBP image on 32-bit platforms in golang.org/x/image Parsing a WEBP image with an invalid, large size panics on 32-bit platforms. Fixed in
0.42.0
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33809
GHSA-44p7-9xx4-hf2g
GO-2026-4815
Mar 25, 2026
Go Images vulnerable to an out-of-memory error via a crafted TIFF file
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error. Fixed in
0.38.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.36.0
minor
Dependencies (1)
|
|
v0.35.0
minor
9 CVEs
CVE-2026-46603
GO-2026-6222
Aug 14, 2026
Excessive memory allocation during VP8L decoding in golang.org/x/image VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion. Fixed in
0.45.0
Updated Aug 15, 2026 · Source: OSV.dev
CVE-2026-46599
GHSA-q675-qj96-32m9
GO-2026-5032
Jul 02, 2026
golang.org/x/image/tiff has excessive resource consumption in PackBits decompression
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data. Fixed in
0.41.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46604
GO-2026-5066
Jun 26, 2026
Panic decoding image with out-of-bounds strip offset in x/image/tiff in golang.org/x/image The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset. Fixed in
0.43.0
Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-46602
GO-2026-5062
Jun 18, 2026
Lack of limit on tile sizes in x/image/tiff in golang.org/x/image The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-46601
GO-2026-5061
Jun 18, 2026
Panic on VP8 alpha channel size mismatch in x/image/webp in golang.org/x/image The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-42500
GO-2026-5031
May 29, 2026
Panic when reading out of bound palette index in golang.org/x/image/bmp Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image. Fixed in
0.41.0
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-33812
GO-2026-4962
Apr 21, 2026
Excessive memory allocation when decoding malicious SFNT in golang.org/x/image Parsing a malicious font file can cause excessive memory allocation. Fixed in
0.39.0
Updated May 14, 2026 · Source: OSV.dev
CVE-2026-33813
GO-2026-4961
Apr 21, 2026
Panic when decoding large WEBP image on 32-bit platforms in golang.org/x/image Parsing a WEBP image with an invalid, large size panics on 32-bit platforms. Fixed in
0.42.0
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33809
GHSA-44p7-9xx4-hf2g
GO-2026-4815
Mar 25, 2026
Go Images vulnerable to an out-of-memory error via a crafted TIFF file
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error. Fixed in
0.38.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.35.0
minor
Dependencies (1)
|
|
v0.34.0
minor
9 CVEs
CVE-2026-46603
GO-2026-6222
Aug 14, 2026
Excessive memory allocation during VP8L decoding in golang.org/x/image VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion. Fixed in
0.45.0
Updated Aug 15, 2026 · Source: OSV.dev
CVE-2026-46599
GHSA-q675-qj96-32m9
GO-2026-5032
Jul 02, 2026
golang.org/x/image/tiff has excessive resource consumption in PackBits decompression
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data. Fixed in
0.41.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46604
GO-2026-5066
Jun 26, 2026
Panic decoding image with out-of-bounds strip offset in x/image/tiff in golang.org/x/image The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset. Fixed in
0.43.0
Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-46602
GO-2026-5062
Jun 18, 2026
Lack of limit on tile sizes in x/image/tiff in golang.org/x/image The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-46601
GO-2026-5061
Jun 18, 2026
Panic on VP8 alpha channel size mismatch in x/image/webp in golang.org/x/image The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-42500
GO-2026-5031
May 29, 2026
Panic when reading out of bound palette index in golang.org/x/image/bmp Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image. Fixed in
0.41.0
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-33812
GO-2026-4962
Apr 21, 2026
Excessive memory allocation when decoding malicious SFNT in golang.org/x/image Parsing a malicious font file can cause excessive memory allocation. Fixed in
0.39.0
Updated May 14, 2026 · Source: OSV.dev
CVE-2026-33813
GO-2026-4961
Apr 21, 2026
Panic when decoding large WEBP image on 32-bit platforms in golang.org/x/image Parsing a WEBP image with an invalid, large size panics on 32-bit platforms. Fixed in
0.42.0
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33809
GHSA-44p7-9xx4-hf2g
GO-2026-4815
Mar 25, 2026
Go Images vulnerable to an out-of-memory error via a crafted TIFF file
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error. Fixed in
0.38.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.34.0
minor
Dependencies (1)
|
|
v0.33.0
minor
9 CVEs
CVE-2026-46603
GO-2026-6222
Aug 14, 2026
Excessive memory allocation during VP8L decoding in golang.org/x/image VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion. Fixed in
0.45.0
Updated Aug 15, 2026 · Source: OSV.dev
CVE-2026-46599
GHSA-q675-qj96-32m9
GO-2026-5032
Jul 02, 2026
golang.org/x/image/tiff has excessive resource consumption in PackBits decompression
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data. Fixed in
0.41.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46604
GO-2026-5066
Jun 26, 2026
Panic decoding image with out-of-bounds strip offset in x/image/tiff in golang.org/x/image The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset. Fixed in
0.43.0
Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-46602
GO-2026-5062
Jun 18, 2026
Lack of limit on tile sizes in x/image/tiff in golang.org/x/image The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-46601
GO-2026-5061
Jun 18, 2026
Panic on VP8 alpha channel size mismatch in x/image/webp in golang.org/x/image The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-42500
GO-2026-5031
May 29, 2026
Panic when reading out of bound palette index in golang.org/x/image/bmp Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image. Fixed in
0.41.0
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-33812
GO-2026-4962
Apr 21, 2026
Excessive memory allocation when decoding malicious SFNT in golang.org/x/image Parsing a malicious font file can cause excessive memory allocation. Fixed in
0.39.0
Updated May 14, 2026 · Source: OSV.dev
CVE-2026-33813
GO-2026-4961
Apr 21, 2026
Panic when decoding large WEBP image on 32-bit platforms in golang.org/x/image Parsing a WEBP image with an invalid, large size panics on 32-bit platforms. Fixed in
0.42.0
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33809
GHSA-44p7-9xx4-hf2g
GO-2026-4815
Mar 25, 2026
Go Images vulnerable to an out-of-memory error via a crafted TIFF file
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error. Fixed in
0.38.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.33.0
minor
Dependencies (1)
|
|
v0.32.0
minor
9 CVEs
CVE-2026-46603
GO-2026-6222
Aug 14, 2026
Excessive memory allocation during VP8L decoding in golang.org/x/image VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion. Fixed in
0.45.0
Updated Aug 15, 2026 · Source: OSV.dev
CVE-2026-46599
GHSA-q675-qj96-32m9
GO-2026-5032
Jul 02, 2026
golang.org/x/image/tiff has excessive resource consumption in PackBits decompression
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data. Fixed in
0.41.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46604
GO-2026-5066
Jun 26, 2026
Panic decoding image with out-of-bounds strip offset in x/image/tiff in golang.org/x/image The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset. Fixed in
0.43.0
Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-46602
GO-2026-5062
Jun 18, 2026
Lack of limit on tile sizes in x/image/tiff in golang.org/x/image The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-46601
GO-2026-5061
Jun 18, 2026
Panic on VP8 alpha channel size mismatch in x/image/webp in golang.org/x/image The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-42500
GO-2026-5031
May 29, 2026
Panic when reading out of bound palette index in golang.org/x/image/bmp Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image. Fixed in
0.41.0
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-33812
GO-2026-4962
Apr 21, 2026
Excessive memory allocation when decoding malicious SFNT in golang.org/x/image Parsing a malicious font file can cause excessive memory allocation. Fixed in
0.39.0
Updated May 14, 2026 · Source: OSV.dev
CVE-2026-33813
GO-2026-4961
Apr 21, 2026
Panic when decoding large WEBP image on 32-bit platforms in golang.org/x/image Parsing a WEBP image with an invalid, large size panics on 32-bit platforms. Fixed in
0.42.0
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33809
GHSA-44p7-9xx4-hf2g
GO-2026-4815
Mar 25, 2026
Go Images vulnerable to an out-of-memory error via a crafted TIFF file
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error. Fixed in
0.38.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.32.0
minor
Dependencies (1)
|
|
v0.31.0
minor
9 CVEs
CVE-2026-46603
GO-2026-6222
Aug 14, 2026
Excessive memory allocation during VP8L decoding in golang.org/x/image VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion. Fixed in
0.45.0
Updated Aug 15, 2026 · Source: OSV.dev
CVE-2026-46599
GHSA-q675-qj96-32m9
GO-2026-5032
Jul 02, 2026
golang.org/x/image/tiff has excessive resource consumption in PackBits decompression
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data. Fixed in
0.41.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46604
GO-2026-5066
Jun 26, 2026
Panic decoding image with out-of-bounds strip offset in x/image/tiff in golang.org/x/image The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset. Fixed in
0.43.0
Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-46602
GO-2026-5062
Jun 18, 2026
Lack of limit on tile sizes in x/image/tiff in golang.org/x/image The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-46601
GO-2026-5061
Jun 18, 2026
Panic on VP8 alpha channel size mismatch in x/image/webp in golang.org/x/image The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-42500
GO-2026-5031
May 29, 2026
Panic when reading out of bound palette index in golang.org/x/image/bmp Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image. Fixed in
0.41.0
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-33812
GO-2026-4962
Apr 21, 2026
Excessive memory allocation when decoding malicious SFNT in golang.org/x/image Parsing a malicious font file can cause excessive memory allocation. Fixed in
0.39.0
Updated May 14, 2026 · Source: OSV.dev
CVE-2026-33813
GO-2026-4961
Apr 21, 2026
Panic when decoding large WEBP image on 32-bit platforms in golang.org/x/image Parsing a WEBP image with an invalid, large size panics on 32-bit platforms. Fixed in
0.42.0
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33809
GHSA-44p7-9xx4-hf2g
GO-2026-4815
Mar 25, 2026
Go Images vulnerable to an out-of-memory error via a crafted TIFF file
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error. Fixed in
0.38.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.31.0
minor
Dependencies (1)
|
|
v0.30.0
minor
9 CVEs
CVE-2026-46603
GO-2026-6222
Aug 14, 2026
Excessive memory allocation during VP8L decoding in golang.org/x/image VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion. Fixed in
0.45.0
Updated Aug 15, 2026 · Source: OSV.dev
CVE-2026-46599
GHSA-q675-qj96-32m9
GO-2026-5032
Jul 02, 2026
golang.org/x/image/tiff has excessive resource consumption in PackBits decompression
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data. Fixed in
0.41.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46604
GO-2026-5066
Jun 26, 2026
Panic decoding image with out-of-bounds strip offset in x/image/tiff in golang.org/x/image The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset. Fixed in
0.43.0
Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-46602
GO-2026-5062
Jun 18, 2026
Lack of limit on tile sizes in x/image/tiff in golang.org/x/image The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-46601
GO-2026-5061
Jun 18, 2026
Panic on VP8 alpha channel size mismatch in x/image/webp in golang.org/x/image The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-42500
GO-2026-5031
May 29, 2026
Panic when reading out of bound palette index in golang.org/x/image/bmp Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image. Fixed in
0.41.0
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-33812
GO-2026-4962
Apr 21, 2026
Excessive memory allocation when decoding malicious SFNT in golang.org/x/image Parsing a malicious font file can cause excessive memory allocation. Fixed in
0.39.0
Updated May 14, 2026 · Source: OSV.dev
CVE-2026-33813
GO-2026-4961
Apr 21, 2026
Panic when decoding large WEBP image on 32-bit platforms in golang.org/x/image Parsing a WEBP image with an invalid, large size panics on 32-bit platforms. Fixed in
0.42.0
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33809
GHSA-44p7-9xx4-hf2g
GO-2026-4815
Mar 25, 2026
Go Images vulnerable to an out-of-memory error via a crafted TIFF file
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error. Fixed in
0.38.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.30.0
minor
Dependencies (1)
|
|
v0.29.0
minor
9 CVEs
CVE-2026-46603
GO-2026-6222
Aug 14, 2026
Excessive memory allocation during VP8L decoding in golang.org/x/image VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion. Fixed in
0.45.0
Updated Aug 15, 2026 · Source: OSV.dev
CVE-2026-46599
GHSA-q675-qj96-32m9
GO-2026-5032
Jul 02, 2026
golang.org/x/image/tiff has excessive resource consumption in PackBits decompression
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data. Fixed in
0.41.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46604
GO-2026-5066
Jun 26, 2026
Panic decoding image with out-of-bounds strip offset in x/image/tiff in golang.org/x/image The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset. Fixed in
0.43.0
Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-46602
GO-2026-5062
Jun 18, 2026
Lack of limit on tile sizes in x/image/tiff in golang.org/x/image The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-46601
GO-2026-5061
Jun 18, 2026
Panic on VP8 alpha channel size mismatch in x/image/webp in golang.org/x/image The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-42500
GO-2026-5031
May 29, 2026
Panic when reading out of bound palette index in golang.org/x/image/bmp Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image. Fixed in
0.41.0
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-33812
GO-2026-4962
Apr 21, 2026
Excessive memory allocation when decoding malicious SFNT in golang.org/x/image Parsing a malicious font file can cause excessive memory allocation. Fixed in
0.39.0
Updated May 14, 2026 · Source: OSV.dev
CVE-2026-33813
GO-2026-4961
Apr 21, 2026
Panic when decoding large WEBP image on 32-bit platforms in golang.org/x/image Parsing a WEBP image with an invalid, large size panics on 32-bit platforms. Fixed in
0.42.0
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33809
GHSA-44p7-9xx4-hf2g
GO-2026-4815
Mar 25, 2026
Go Images vulnerable to an out-of-memory error via a crafted TIFF file
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error. Fixed in
0.38.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.29.0
minor
Dependencies (1)
|
|
v0.28.0
minor
9 CVEs
CVE-2026-46603
GO-2026-6222
Aug 14, 2026
Excessive memory allocation during VP8L decoding in golang.org/x/image VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion. Fixed in
0.45.0
Updated Aug 15, 2026 · Source: OSV.dev
CVE-2026-46599
GHSA-q675-qj96-32m9
GO-2026-5032
Jul 02, 2026
golang.org/x/image/tiff has excessive resource consumption in PackBits decompression
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data. Fixed in
0.41.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46604
GO-2026-5066
Jun 26, 2026
Panic decoding image with out-of-bounds strip offset in x/image/tiff in golang.org/x/image The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset. Fixed in
0.43.0
Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-46602
GO-2026-5062
Jun 18, 2026
Lack of limit on tile sizes in x/image/tiff in golang.org/x/image The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-46601
GO-2026-5061
Jun 18, 2026
Panic on VP8 alpha channel size mismatch in x/image/webp in golang.org/x/image The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-42500
GO-2026-5031
May 29, 2026
Panic when reading out of bound palette index in golang.org/x/image/bmp Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image. Fixed in
0.41.0
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-33812
GO-2026-4962
Apr 21, 2026
Excessive memory allocation when decoding malicious SFNT in golang.org/x/image Parsing a malicious font file can cause excessive memory allocation. Fixed in
0.39.0
Updated May 14, 2026 · Source: OSV.dev
CVE-2026-33813
GO-2026-4961
Apr 21, 2026
Panic when decoding large WEBP image on 32-bit platforms in golang.org/x/image Parsing a WEBP image with an invalid, large size panics on 32-bit platforms. Fixed in
0.42.0
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33809
GHSA-44p7-9xx4-hf2g
GO-2026-4815
Mar 25, 2026
Go Images vulnerable to an out-of-memory error via a crafted TIFF file
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error. Fixed in
0.38.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.28.0
minor
Dependencies (1)
|
|
v0.27.0
minor
9 CVEs
CVE-2026-46603
GO-2026-6222
Aug 14, 2026
Excessive memory allocation during VP8L decoding in golang.org/x/image VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion. Fixed in
0.45.0
Updated Aug 15, 2026 · Source: OSV.dev
CVE-2026-46599
GHSA-q675-qj96-32m9
GO-2026-5032
Jul 02, 2026
golang.org/x/image/tiff has excessive resource consumption in PackBits decompression
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data. Fixed in
0.41.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46604
GO-2026-5066
Jun 26, 2026
Panic decoding image with out-of-bounds strip offset in x/image/tiff in golang.org/x/image The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset. Fixed in
0.43.0
Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-46602
GO-2026-5062
Jun 18, 2026
Lack of limit on tile sizes in x/image/tiff in golang.org/x/image The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-46601
GO-2026-5061
Jun 18, 2026
Panic on VP8 alpha channel size mismatch in x/image/webp in golang.org/x/image The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-42500
GO-2026-5031
May 29, 2026
Panic when reading out of bound palette index in golang.org/x/image/bmp Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image. Fixed in
0.41.0
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-33812
GO-2026-4962
Apr 21, 2026
Excessive memory allocation when decoding malicious SFNT in golang.org/x/image Parsing a malicious font file can cause excessive memory allocation. Fixed in
0.39.0
Updated May 14, 2026 · Source: OSV.dev
CVE-2026-33813
GO-2026-4961
Apr 21, 2026
Panic when decoding large WEBP image on 32-bit platforms in golang.org/x/image Parsing a WEBP image with an invalid, large size panics on 32-bit platforms. Fixed in
0.42.0
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33809
GHSA-44p7-9xx4-hf2g
GO-2026-4815
Mar 25, 2026
Go Images vulnerable to an out-of-memory error via a crafted TIFF file
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error. Fixed in
0.38.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.27.0
minor
Dependencies (1)
|
|
v0.26.0
initial
9 CVEs
CVE-2026-46603
GO-2026-6222
Aug 14, 2026
Excessive memory allocation during VP8L decoding in golang.org/x/image VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion. Fixed in
0.45.0
Updated Aug 15, 2026 · Source: OSV.dev
CVE-2026-46599
GHSA-q675-qj96-32m9
GO-2026-5032
Jul 02, 2026
golang.org/x/image/tiff has excessive resource consumption in PackBits decompression
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data. Fixed in
0.41.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46604
GO-2026-5066
Jun 26, 2026
Panic decoding image with out-of-bounds strip offset in x/image/tiff in golang.org/x/image The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset. Fixed in
0.43.0
Updated Jun 27, 2026 · Source: OSV.dev
CVE-2026-46602
GO-2026-5062
Jun 18, 2026
Lack of limit on tile sizes in x/image/tiff in golang.org/x/image The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-46601
GO-2026-5061
Jun 18, 2026
Panic on VP8 alpha channel size mismatch in x/image/webp in golang.org/x/image The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size. Fixed in
0.43.0
Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-42500
GO-2026-5031
May 29, 2026
Panic when reading out of bound palette index in golang.org/x/image/bmp Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image. Fixed in
0.41.0
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-33812
GO-2026-4962
Apr 21, 2026
Excessive memory allocation when decoding malicious SFNT in golang.org/x/image Parsing a malicious font file can cause excessive memory allocation. Fixed in
0.39.0
Updated May 14, 2026 · Source: OSV.dev
CVE-2026-33813
GO-2026-4961
Apr 21, 2026
Panic when decoding large WEBP image on 32-bit platforms in golang.org/x/image Parsing a WEBP image with an invalid, large size panics on 32-bit platforms. Fixed in
0.42.0
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33809
GHSA-44p7-9xx4-hf2g
GO-2026-4815
Mar 25, 2026
Go Images vulnerable to an out-of-memory error via a crafted TIFF file
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error. Fixed in
0.38.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v0.26.0
initial
Dependencies (1)
|