Memory Exhaustion Vulnerability in VP8L Decoding of Go Programming Language
CVE-2026-46603
Currently unrated
What is CVE-2026-46603?
In the Go programming language's VP8L decoding module, improper handling of crafted VP8L images can lead to excessive memory allocation. Attackers leveraging this vulnerability may create malformed images containing numerous unused Huffman tree groups, resulting in memory exhaustion and potential denial of service. This flaw primarily affects versions of Go starting from 1.20, emphasizing the need for timely updates to mitigate the risks associated with this defect.
Affected Version(s)
golang.org/x/image/vp8l 0 < 0.45.0
