Unknown · Golang.Org/X/Image/Vp8L · CVE-2026-46603
**Name of the Vulnerable Software and Affected Versions**
golang.org/x/image/vp8l (affected versions not specified)
**Description**
VP8L decoding in the golang.org/x/image/vp8l package can allocate an excessive amount of memory when processing a specially crafted VP8L image that contains numerous unused Huffman tree groups. This behavior allows a remote attacker to trigger a denial of service through memory exhaustion.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.