CVE-2026-42500
Panic when reading out of bound palette index in golang.org/x/image/bmp
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image.
| Vendor | golang.org/x/image |
| Product | golang.org/x/image/bmp |
| Published | May 29, 2026 |
| Last Updated | May 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for golang.org/x/image golang.org/x/image/bmp
Be the first to know when new medium vulnerabilities affecting golang.org/x/image golang.org/x/image/bmp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
golang.org/x/image / golang.org/x/image/bmp
0 < 0.41.0