CVE-2026-46599
published 2026-05-29CVE-2026-46599: The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.35%
28.0th percentile
The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cryostat | cryostat-storage-rhel9 | — | — |
| golang.org | x_image | >= 0 < 0.41.0 | 0.41.0 |
| golang.org | x_image_golang.org_x_image_tiff | < 0.41.0 | 0.41.0 |
| openshift-logging | cluster-logging-rhel9-operator | — | — |
| openshift4 | ose-tests-rhel9 | — | — |
| rhacm2 | volsync-rhel9 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
golang.org/x/image/tiff has excessive resource consumption in PackBits decompression
ghsa·2026-07-02
CVE-2026-46599 [HIGH] CWE-770 golang.org/x/image/tiff has excessive resource consumption in PackBits decompression
golang.org/x/image/tiff has excessive resource consumption in PackBits decompression
The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data.
VulDB
x-image-tiff up to 0.40.x on Go TIFF Decoder width/height allocation of resources (EUVD-2026-33432 / Nessus ID 318030)
vuldb·2026-05-30
CVE-2026-46599 [LOW] x-image-tiff up to 0.40.x on Go TIFF Decoder width/height allocation of resources (EUVD-2026-33432 / Nessus ID 318030)
A vulnerability, which was classified as problematic, has been found in x-image-tiff up to 0.40.x on Go. Affected by this vulnerability is an unknown functionality of the component TIFF Decoder. Performing a manipulation of the argument width/height results in allocation of resources.
This vulnerability is cataloged as CVE-2026-46599. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
Red Hat
golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data
vendor_redhat·2026-05-29·CVSS 7.5
CVE-2026-46599 [HIGH] CWE-770 golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data
golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data
The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data.
A flaw was found in the `golang.org/x/image/tiff` package's TIFF decoder. This vulnerability occurs because the decoder does not properly limit the size of PackBits-compressed data. A remote attacker could exploit this by providing a maliciously-crafted image, leading to the decoder processing excessive amounts of data. This can result in a Denial of Service (DoS) due to resource exhaustion, even with a small input image.
S
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-46599 cliphist: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data [fedora-all]
bugzilla·2026-06-29·CVSS 7.5
CVE-2026-46599 [HIGH] CVE-2026-46599 cliphist: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data [fedora-all]
CVE-2026-46599 cliphist: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data.
Bugzilla
CVE-2026-46599 golang-x-image: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data [fedora-all]
bugzilla·2026-06-29·CVSS 7.5
CVE-2026-46599 [HIGH] CVE-2026-46599 golang-x-image: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data [fedora-all]
CVE-2026-46599 golang-x-image: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data.
Bugzilla
CVE-2026-46599 ollama: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data [fedora-all]
bugzilla·2026-06-29·CVSS 7.5
CVE-2026-46599 [HIGH] CVE-2026-46599 ollama: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data [fedora-all]
CVE-2026-46599 ollama: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data.
Bugzilla
CVE-2026-46599 hugo: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data [fedora-all]
bugzilla·2026-06-29·CVSS 7.5
CVE-2026-46599 [HIGH] CVE-2026-46599 hugo: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data [fedora-all]
CVE-2026-46599 hugo: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data.
Bugzilla
CVE-2026-46599 aerc: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data [fedora-all]
bugzilla·2026-06-29·CVSS 7.5
CVE-2026-46599 [HIGH] CVE-2026-46599 aerc: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data [fedora-all]
CVE-2026-46599 aerc: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data.
Bugzilla
CVE-2026-46599 golang-x-perf: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data [fedora-all]
bugzilla·2026-06-29·CVSS 7.5
CVE-2026-46599 [HIGH] CVE-2026-46599 golang-x-perf: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data [fedora-all]
CVE-2026-46599 golang-x-perf: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data.
Bugzilla
CVE-2026-46599 golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data
bugzilla·2026-05-29·CVSS 7.5
CVE-2026-46599 [HIGH] CVE-2026-46599 golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data
CVE-2026-46599 golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data
The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data.
2026-05-29
Published