CVE-2026-46599
Excessive resource consumption in PackBits decompression in golang.org/x/image/tiff
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
5th
The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data.
| Vendor | golang.org/x/image |
| Product | golang.org/x/image/tiff |
| Published | May 29, 2026 |
| Last Updated | Jun 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for golang.org/x/image golang.org/x/image/tiff
Be the first to know when new high vulnerabilities affecting golang.org/x/image golang.org/x/image/tiff are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
golang.org/x/image / golang.org/x/image/tiff
0 < 0.41.0
References
Credits
Uuganbayar Lkhamsuren