VYPR
High severity7.5NVD Advisory· Published May 29, 2026· Updated Jul 22, 2026

CVE-2026-46599

CVE-2026-46599

Description

The TIFF decoder in golang.org/x/image lacks size limits for PackBits-compressed data, allowing a small malicious image to trigger excessive resource consumption.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
golang.org/x/imageGo
< 0.41.00.41.0

Affected products

24

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.