cbcvebase.
CVE-2026-33813
published 2026-04-21

CVE-2026-33813: Parsing a WEBP image with an invalid, large size panics on 32-bit platforms.

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
Parsing a WEBP image with an invalid, large size panics on 32-bit platforms.

Affected

16 ranges
VendorProductVersion rangeFixed in
ansible-automation-platformplatform-operator-bundle
cryostatcryostat-storage-rhel9
go-toolset_rhel8golang
golang.orgx_image_golang.org_x_image_webp< 0.39.00.39.0
golangimage< 0.39.00.39.0
multicluster-globalhubmulticluster-globalhub-grafana-rhel9
openshift-gitops-1argocd-rhel8
openshift-gitops-1argocd-rhel9
openshift-loggingcluster-logging-rhel9-operator
openshift-serverless-1kn-plugin-event-sender-rhel9
openshift-service-meshistio-rhel8-operator
openshift4ose-tests-rhel9
rhacm2acm-grafana-rhel9
rhacm2volsync-rhel9
rhoaiodh-model-registry-rhel9
rhoso-operatorsopenstack-operator-bundle