CVE-2026-46602 in golang.org/x/image
- golang.org/x/image
Summary
The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption. All versions prior to v0.43.0 are affected.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- NONE
- NONE
- HIGH
Advisory Timeline
- Published