The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 25 Jun 2026 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
CWE-789

Thu, 25 Jun 2026 20:00:00 +0000

Type Values Removed Values Added
Description The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption.
Title Lack of limit on tile sizes in x/image/tiff in golang.org/x/image
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published:

Updated: 2026-06-25T19:47:21.690Z

Reserved: 2026-05-15T17:35:00.814Z

Link: CVE-2026-46602

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-25T21:45:15Z

Weaknesses