{"id":"CVE-2026-46603","title":"golang.org/x/image/vp8l: golang.org/x/image/vp8l: Denial of Service via excessive memory allocation (CVE-2026-46603)","summary":"A flaw was found in golang.org/x/image/vp8l. A remote attacker can cause a denial of service by providing a specially crafted VP8L image. This image, containing many unused Huffman tree groups, leads to excessive memory allocation during V…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-770","vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2.16","affected":["cryostat 4","advanced_cluster_management_for_kubernetes 2.16","advanced_cluster_management_for_kubernetes 2.17"],"patched":["advanced_cluster_management_for_kubernetes 2.16","advanced_cluster_management_for_kubernetes 2.17"],"published":"2026-08-14","updated":"2026-09-24","sourceUpdated":"2026-09-24T05:55:07+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46603.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46603.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-46603"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2516086"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-46603"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46603"},{"url":"https://go.dev/cl/793460"},{"url":"https://go.dev/issue/80069"},{"url":"https://pkg.go.dev/vuln/GO-2026-6222"},{"url":"https://access.redhat.com/errata/RHSA-2026:71116"},{"url":"https://access.redhat.com/errata/RHSA-2026:71117"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.00417,"epssPercentile":0.35745,"aliases":["GO-2026-6222"],"ecosystem":"go","ingestedAt":"2026-08-14T19:18:46.763Z","slug":"CVE-2026-46603","body":"## Overview\n\nA flaw was found in golang.org/x/image/vp8l. A remote attacker can cause a denial of service by providing a specially crafted VP8L image. This image, containing many unused Huffman tree groups, leads to excessive memory allocation during VP8L decoding, resulting in memory exhaustion.\n\n## Vendor advisories\n\n- **RHSA-2026:71116** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.16 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71116)\n- **RHSA-2026:71117** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.17 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71117)\n- **Red Hat VEX** · Important · affected: Cryostat 4 · no fix planned: Cryostat 4 · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46603.json)\n\n**golang.org/x/image/vp8l: golang.org/x/image/vp8l: Denial of Service via excessive memory allocation** — rated Important by Red Hat. Released 2026-08-14, updated 2026-09-24.\n\nAffected:\n\n- Cryostat 4\n\nFixed:\n\n- Red Hat Advanced Cluster Management for Kubernetes 2.16\n- Red Hat Advanced Cluster Management for Kubernetes 2.17\n\nNo fix planned:\n\n- Cryostat 4\n\nNot affected:\n\n- Red Hat Advanced Cluster Management for Kubernetes 2.16\n- Red Hat Advanced Cluster Management for Kubernetes 2.17\n\n## Remediation\n\nFor more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:\n\nhttps://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.16/html/business_continuity/business-cont-overview#volsync https://access.redhat.com/errata/RHSA-2026:71116\nFor more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:\n\nhttps://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.17/html/business_continuity/business-cont-overview#volsync https://access.redhat.com/errata/RHSA-2026:71117\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.\n\n## Package advisory (CVE-2026-46603)\n\nAffected packages:\n\n- `golang.org/x/image < 0.45.0`\n\nPatched in:\n\n- `golang.org/x/image 0.45.0`\n\nSource: https://osv.dev/vulnerability/GO-2026-6222","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":209985,"id":"CVE-2026-46603","ts":1790235621860,"field":"cvss","old":null,"new":"7.5"},{"seq":209984,"id":"CVE-2026-46603","ts":1790235621860,"field":"severity","old":"none","new":"high"}]}