The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data.
Metrics
Affected Vendors & Products
References
History
Mon, 01 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-400 |
Mon, 01 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-770 | |
| Metrics |
cvssV3_1
|
Sat, 30 May 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Golang
Golang image |
|
| Vendors & Products |
Golang
Golang image |
Fri, 29 May 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-400 |
Fri, 29 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data. | |
| Title | Excessive resource consumption in PackBits decompression in golang.org/x/image/tiff | |
| References |
|
Status: PUBLISHED
Assigner: Go
Published: 2026-05-29T19:35:33.539Z
Updated: 2026-06-01T14:44:03.725Z
Reserved: 2026-05-15T17:35:00.813Z
Link: CVE-2026-46599
Updated: 2026-06-01T14:43:29.816Z
Status : Deferred
Published: 2026-05-29T20:16:28.280
Modified: 2026-06-01T18:16:02.273
Link: CVE-2026-46599
No data.