Executive brief
A vulnerability in the Go TIFF image decoding library could allow an attacker to crash an application or cause a denial-of-service. By providing a specially crafted, small image file, an attacker can force the system to consume excessive processing power and memory during decompression. This can lead to service outages or significant performance degradation for any application that processes user-uploaded TIFF images.
Technical details
A resource exhaustion vulnerability exists in the golang.org/x/image/tiff package due to a lack of size limits on PackBits-compressed data. The 'unpackBits' and 'Decode' functions in the TIFF decoder do not validate the ratio of compressed to decompressed data, allowing a small input file to expand into a massive amount of data in memory. An unauthenticated remote attacker can exploit this by submitting a specially crafted TIFF image to an application using the library, leading to a denial-of-service (DoS) via CPU and memory exhaustion. The issue is addressed in version 0.41.0 by implementing limits on the amount of PackBits-compressed data the decoder will process.
Affected products
- Go golang.org/x/image/tiff < 0.41.0
Timeline
- 2026-05-21: disclosed: Issue reported to Go project by Uuganbayar Lkhamsuren
- 2026-05-29: advisory: NVD published CVE-2026-46599
- 2026-07-02: patched: GitHub Advisory published and version 0.41.0 released