Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-33809

Опубликовано: 25 мар. 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:golang:tiff:*:*:*:*:*:go:*:*
Версия до 0.38.0 (исключая)

EPSS

Процентиль: 25%
0.00328
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 5.3
ubuntu
4 месяца назад

A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.

CVSS3: 6.5
redhat
4 месяца назад

A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.

CVSS3: 5.3
debian
4 месяца назад

A maliciously crafted TIFF file can cause image decoding to attempt to ...

CVSS3: 5.3
github
4 месяца назад

Go Images vulnerable to an out-of-memory error via a crafted TIFF file

CVSS3: 5.3
fstec
4 месяца назад

Уязвимость библиотеки golang.org/x/image/tiff языка программирования Go, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 25%
0.00328
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-434