---
id: CVE-2026-46603
title: >-
  golang.org/x/image/vp8l: golang.org/x/image/vp8l: Denial of Service via
  excessive memory allocation (CVE-2026-46603)
summary: >-
  A flaw was found in golang.org/x/image/vp8l. A remote attacker can cause a
  denial of service by providing a specially crafted VP8L image. This image,
  containing many unused Huffman tree groups, leads to excessive memory
  allocation during V…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-770
vendor: Red Hat
product: Red Hat Advanced Cluster Management for Kubernetes 2.16
affected:
  - cryostat 4
  - advanced_cluster_management_for_kubernetes 2.16
  - advanced_cluster_management_for_kubernetes 2.17
patched:
  - advanced_cluster_management_for_kubernetes 2.16
  - advanced_cluster_management_for_kubernetes 2.17
published: '2026-08-14'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T05:55:07+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46603.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46603.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-46603'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2516086'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-46603'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-46603'
  - url: 'https://go.dev/cl/793460'
  - url: 'https://go.dev/issue/80069'
  - url: 'https://pkg.go.dev/vuln/GO-2026-6222'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71116'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71117'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.0075
epssPercentile: 0.53102
aliases:
  - GO-2026-6222
ecosystem: go
ingestedAt: '2026-08-14T19:18:46.763Z'
---

## Overview

A flaw was found in golang.org/x/image/vp8l. A remote attacker can cause a denial of service by providing a specially crafted VP8L image. This image, containing many unused Huffman tree groups, leads to excessive memory allocation during VP8L decoding, resulting in memory exhaustion.

## Vendor advisories

- **RHSA-2026:71116** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.16 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71116)
- **RHSA-2026:71117** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.17 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71117)
- **Red Hat VEX** · Important · affected: Cryostat 4 · no fix planned: Cryostat 4 · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46603.json)

**golang.org/x/image/vp8l: golang.org/x/image/vp8l: Denial of Service via excessive memory allocation** — rated Important by Red Hat. Released 2026-08-14, updated 2026-09-24.

Affected:

- Cryostat 4

Fixed:

- Red Hat Advanced Cluster Management for Kubernetes 2.16
- Red Hat Advanced Cluster Management for Kubernetes 2.17

No fix planned:

- Cryostat 4

Not affected:

- Red Hat Advanced Cluster Management for Kubernetes 2.16
- Red Hat Advanced Cluster Management for Kubernetes 2.17

## Remediation

For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:

https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.16/html/business_continuity/business-cont-overview#volsync https://access.redhat.com/errata/RHSA-2026:71116
For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:

https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.17/html/business_continuity/business-cont-overview#volsync https://access.redhat.com/errata/RHSA-2026:71117

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

## Package advisory (CVE-2026-46603)

Affected packages:

- `golang.org/x/image < 0.45.0`

Patched in:

- `golang.org/x/image 0.45.0`

Source: https://osv.dev/vulnerability/GO-2026-6222
