Loading HuntDB...

GHSA-9phm-fm57-rhg8

GitHub Security Advisory

Panic when parsing invalid palette-color images in golang.org/x/image

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Parsing a corrupt or malicious image with invalid color indices can cause a panic.

Affected Packages

Go golang.org/x/image
Affected versions: 0 (fixed in 0.18.0)

Related CVEs

Key Information

GHSA ID
GHSA-9phm-fm57-rhg8
Published
June 26, 2024 7:26 PM
Last Modified
August 2, 2024 3:50 PM
CVSS Score
7.5 /10
Primary Ecosystem
Go
Primary Package
golang.org/x/image
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 19, 2025 6:27 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.