Vulnerability Report: GO-2026-4815
- CVE-2026-33809, GHSA-44p7-9xx4-hf2g
- Affects: golang.org/x/image
- Published: Mar 25, 2026
- Modified: Apr 06, 2026
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.
Affected Packages
-
PathGo VersionsSymbols
-
before v0.38.0
Aliases
References
Credits
- Andy Gill, ZephrSec Ltd
Feedback
See anything missing or incorrect?
Suggest an edit to this report.