GHSA-qgc7-mgm3-q253
GitHub Security Advisory
Uncontrolled Resource Consumption in golang.org/x/image
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. This could lead to a denial of service.
Affected Packages
Go
golang.org/x/image
Affected versions:
0
(fixed in 0.5.0)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 19, 2025 6:27 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.