VYPR
Medium severity5.5NVD Advisory· Published Feb 28, 2023· Updated Jun 17, 2026

CVE-2022-41727

CVE-2022-41727

Description

An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. This could lead to a denial of service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
golang.org/x/imageGo
< 0.5.00.5.0

Affected products

6
  • golang.org/x/image/golang.org/x/image/tiffv5
    Range: 0
  • ghsa-coords
    Range: < 0.5.0
  • cpe:2.3:a:golang:image:*:*:*:*:*:go:*:*
    Range: <0.5.0
  • cpe:2.3:a:golang:tiff:-:*:*:*:*:go:*:*
  • cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

12

News mentions

0

No linked articles in our index yet.