The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data.
Metrics
Affected Vendors & Products
References
History
Fri, 29 May 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-400 |
Fri, 29 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data. | |
| Title | Excessive resource consumption in PackBits decompression in golang.org/x/image/tiff | |
| References |
|
Status: PUBLISHED
Assigner: Go
Published:
Updated: 2026-05-29T19:35:33.539Z
Reserved: 2026-05-15T17:35:00.813Z
Link: CVE-2026-46599
No data.
Status : Received
Published: 2026-05-29T20:16:28.280
Modified: 2026-05-29T20:16:28.280
Link: CVE-2026-46599
No data.
OpenCVE Enrichment
Updated: 2026-05-29T22:30:09Z