CVE-2026-46603
Received Received - Intake

Memory Exhaustion in Go VP8L Decoding

Vulnerability report for CVE-2026-46603, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-14

Last updated on: 2026-08-14

Assigner: Go Project

Description

VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-14
Last Modified
2026-08-14
Generated
2026-09-03
AI Q&A
2026-08-14
EPSS Evaluated
2026-09-02
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
golang go From 1.0.0 (inc)
golang golang to v0.45.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-789 The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves excessive memory allocation in Go's vp8l image decoder. When processing a crafted VP8L image with many unused Huffman tree groups, the decoder allocates memory for all groups even if they are not used by any tile. This leads to significant memory consumption, potentially up to 1.4 GiB for a small image, causing a denial of service via memory exhaustion.

Detection Guidance

To detect this vulnerability, inspect Go applications using the golang.org/x/image/vp8l package for excessive memory usage when processing VP8L images. Monitor system memory during image processing tasks. Check for crashes or slowdowns when handling crafted images with many unused Huffman tree groups.

Impact Analysis

If you process untrusted VP8L images in Go applications using golang.org/x/image/vp8l before v0.45.0, an attacker could send a malicious image to exhaust system memory. This may crash your application or system, disrupting services and causing downtime.

Compliance Impact

This vulnerability primarily causes denial of service via memory exhaustion, which may indirectly impact compliance with standards like GDPR or HIPAA by disrupting system availability. Excessive memory usage could lead to service outages, potentially affecting data processing or access required for compliance. However, the vulnerability itself does not directly violate these standards unless it results in unauthorized data access or processing failures during critical operations.

Mitigation Strategies

Update the golang.org/x/image package to version v0.45.0 or later. If updating is not possible, restrict processing of untrusted VP8L images or implement memory limits during image decoding. Follow the mitigation approach used in libwebp by discarding unused Huffman tree groups.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-46603. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart