golang.org/x/image vulnerabilities
CVEs whose affected-version data names the golang.org/x/image package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-46599High· 7.5golang.org/x/image/tiff has excessive resource consumption in PackBits decompression
golang.org/x/image/tiff has excessive resource consumption in PackBits decompression
▾ Twilightx · golang.org/x/imageEPSS 0.35%via GHSA
CVE-2026-42500NonePanic when reading out of bound palette index in golang.org/x/image/bmp
Panic when reading out of bound palette index in golang.org/x/image/bmp
▾ Sunlitx · golang.org/x/imageEPSS 0.38%via OSV
CVE-2026-33812NoneExcessive memory allocation when decoding malicious SFNT in golang.org/x/image
Excessive memory allocation when decoding malicious SFNT in golang.org/x/image
▾ Sunlitx · golang.org/x/imageEPSS 0.11%via OSV
CVE-2026-33809Medium· 5.3Go Images vulnerable to an out-of-memory error via a crafted TIFF file
Go Images vulnerable to an out-of-memory error via a crafted TIFF file
▾ Sunlitx · golang.org/x/imageEPSS 0.33%via OSV