Medium severity5.3NVD Advisory· Published Mar 25, 2026· Updated Apr 21, 2026
CVE-2026-33809
CVE-2026-33809
Description
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
golang.org/x/imageGo | < 0.38.0 | 0.38.0 |
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- github.com/advisories/GHSA-44p7-9xx4-hf2gghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-33809ghsaADVISORY
- pkg.go.dev/vuln/GO-2026-4815nvdVendor AdvisoryWEB
- cs.opensource.google/go/x/imageghsaPACKAGE
- go.dev/cl/757660nvdMailing ListWEB
- go.dev/issue/78267nvdIssue TrackingWEB
News mentions
0No linked articles in our index yet.