Vulnerability Report: GO-2026-5061
- CVE-2026-46601
- Affects: golang.org/x/image
- Published: Jun 18, 2026
The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size.
Affected Packages
-
PathGo VersionsSymbols
-
before v0.43.0
-
before v0.43.0all symbols
Aliases
References
Credits
- Lucas Futures (GitHub: gn00295120)
Feedback
See anything missing or incorrect?
Suggest an edit to this report.