CVE-2026-33809
published 2026-03-25CVE-2026-33809: A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.33%
25.4th percentile
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | golang-golang-x-image | < golang-golang-x-image 0.38.0-1 (forky) | golang-golang-x-image 0.38.0-1 (forky) |
| golang.org | x_image | >= 0 < 0.38.0 | 0.38.0 |
| golang.org | x_image_golang.org_x_image_tiff | < 0.38.0 | 0.38.0 |
| golang | tiff | < 0.38.0 | 0.38.0 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
golang: golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via maliciously crafted TIFF file
vendor_redhat·2026-03-25·CVSS 5.3
CVE-2026-33809 [MEDIUM] CWE-1285 golang: golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via maliciously crafted TIFF file
golang: golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via maliciously crafted TIFF file
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.
A flaw was found in golang.org/x/image/tiff. A remote attacker could exploit this vulnerability by providing a maliciously crafted Tagged Image File Format (TIFF) file. This could cause the image decoding process to attempt to allocate up to 4 gigabytes (GiB) of memory. The excessive resource consumption or an out-of-memory error would lead to a Denial of Service (DoS) condition.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Sec
Debian
CVE-2026-33809: golang-golang-x-image - A maliciously crafted TIFF file can cause image decoding to attempt to allocate ...
vendor_debian·2026·CVSS 5.3
CVE-2026-33809 [MEDIUM] CVE-2026-33809: golang-golang-x-image - A maliciously crafted TIFF file can cause image decoding to attempt to allocate ...
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 0.38.0-1)
sid: resolved (fixed in 0.38.0-1)
trixie: open
VulDB
x-image up to 0.37.x on Go TIFF File Parser resource consumption (Nessus ID 303764 / WID-SEC-2026-1653)
vuldb·2026-05-23·CVSS 5.3
CVE-2026-33809 [MEDIUM] x-image up to 0.37.x on Go TIFF File Parser resource consumption (Nessus ID 303764 / WID-SEC-2026-1653)
A vulnerability was found in x-image up to 0.37.x on Go. It has been declared as problematic. This affects an unknown part of the component TIFF File Parser. Such manipulation leads to resource consumption.
This vulnerability is documented as CVE-2026-33809. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
GHSA
Go Images vulnerable to an out-of-memory error via a crafted TIFF file
ghsa·2026-03-25
CVE-2026-33809 [MEDIUM] CWE-770 Go Images vulnerable to an out-of-memory error via a crafted TIFF file
Go Images vulnerable to an out-of-memory error via a crafted TIFF file
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.
OSV
OOM from malicious IFD offset in golang.org/x/image/tiff
osv·2026-03-25
CVE-2026-33809 OOM from malicious IFD offset in golang.org/x/image/tiff
OOM from malicious IFD offset in golang.org/x/image/tiff
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.
OSV
Go Images vulnerable to an out-of-memory error via a crafted TIFF file
osv·2026-03-25
CVE-2026-33809 [MEDIUM] Go Images vulnerable to an out-of-memory error via a crafted TIFF file
Go Images vulnerable to an out-of-memory error via a crafted TIFF file
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.
OSV
CVE-2026-33809: A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an
osv·2026-03-25·CVSS 5.3
CVE-2026-33809 [MEDIUM] CVE-2026-33809: A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-33809 golang: golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via maliciously crafted TIFF file
bugzilla·2026-03-25·CVSS 5.3
CVE-2026-33809 [MEDIUM] CVE-2026-33809 golang: golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via maliciously crafted TIFF file
CVE-2026-33809 golang: golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via maliciously crafted TIFF file
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.
Wiz
CVE-2026-33809 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 10.0
CVE-2026-33809 [CRITICAL] CVE-2026-33809 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33809 :
Rclone vulnerability analysis and mitigation
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.
Source : NVD
## 5.3
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Rclone
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
go-toolset:rhel8::golang-tests
golang-bin
Sources
NVD
Chainguard Has Fix Added at: Mar 31, 2026
Debian 11, 12, 13 Severity MEDIUM No Fix Added at: Mar 29, 2026
Debian 14 Severity MEDIUM Has Fix Added at: Mar 29
2026-03-25
Published