PT-2026-44992 · Debian+5 · Golang-Golang-X-Image+4

·

CVE-2026-46599

·

Published

2026-05-29

·

Updated

2026-07-30

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description The TIFF decoder fails to impose a limit on the size of PackBits-compressed data. This allows a maliciously crafted image, even one with small pixel dimensions and encoded size, to force the decoder to process excessive amounts of compressed data, leading to a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-BP02821
CLEANSTART-2026-YF30779
CVE-2026-46599
GHSA-Q675-QJ96-32M9
GO-2026-5032
OPENSUSE-SU-2026:21483-1

Affected Products

Golang-Golang-X-Image
Golang.Org/X/Image
Golang.Org/X/Image/Tiff
Govulncheck-Vulndb
Rclone