FlawAtlas
Search the atlas
CVE-2026-33809 Moderate

Go Images vulnerable to an out-of-memory error via a crafted TIFF file

A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.

Exploit probability 0.3%
Published March 25, 2026
Required by Not available
Last source change May 5, 2026

02 / AFFECTED SOFTWARE

Affected packages

Go golang.org/x/image
Go golang.org/x/image

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities GO-2026-4815

A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.

View original source
Open Source Vulnerabilities GHSA-44p7-9xx4-hf2g

A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.

View original source

05 / REFERENCES

Further evidence