CVE-2026-46602
published 2026-06-25CVE-2026-46602: The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.34%
25.9th percentile
The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| golang.org | x_image_golang.org_x_image_tiff | < 0.43.0 | 0.43.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
NLnet Labs x-image-tiff up to 0.42.x TIFF Decoder memory allocation
vuldb·2026-06-26
CVE-2026-46602 [LOW] NLnet Labs x-image-tiff up to 0.42.x TIFF Decoder memory allocation
A vulnerability has been found in NLnet Labs x-image-tiff up to 0.42.x and classified as problematic. This vulnerability affects unknown code of the component TIFF Decoder. The manipulation leads to uncontrolled memory allocation.
This vulnerability is traded as CVE-2026-46602. Access to the local network is required for this attack to succeed. There is no exploit available.
The affected component should be upgraded.
GHSA
The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption.
ghsa_unreviewed·2026-06-25
CVE-2026-46602 [HIGH] The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption.
The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-25
Published