CVE-2026-33809
OOM from malicious IFD offset in golang.org/x/image/tiff
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
11th
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.
| Vendor | golang.org/x/image |
| Product | golang.org/x/image/tiff |
| Published | Mar 25, 2026 |
| Last Updated | Apr 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for golang.org/x/image golang.org/x/image/tiff
Be the first to know when new medium vulnerabilities affecting golang.org/x/image golang.org/x/image/tiff are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
golang.org/x/image / golang.org/x/image/tiff
0 < 0.38.0
References
Credits
Andy Gill, ZephrSec Ltd