CVE-2026-46603
Excessive memory allocation during VP8L decoding in golang.org/x/image
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion.
| Vendor | golang.org/x/image |
| Product | golang.org/x/image/vp8l |
| Published | Aug 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for golang.org/x/image golang.org/x/image/vp8l
Be the first to know when new unknown vulnerabilities affecting golang.org/x/image golang.org/x/image/vp8l are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
golang.org/x/image / golang.org/x/image/vp8l
0 < 0.45.0
References
Credits
Daniele Ballarini