CVE-2026-46603

ADVISORY - golang

Summary

VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion.

Common Weakness Enumeration (CWE)


GoLang

CREATED

UPDATED

ADVISORY IDGO-2026-6222
EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY