GO-2026-6222
Dashboard / Vulnerabilities / GO-2026-6222
Summary: Excessive memory allocation during VP8L decoding in golang.org/x/image
Details: VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion.
References: https://go.dev/issue/80069, https://go.dev/cl/793460
Affected packages
Package
Name: golang.org/x/image
Purl: pkg:golang/golang.org/x/image
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -0.45.0
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
