PT-2026-34050 · Debian+6 · Golang-Golang-X-Image+4

Tristan Madani

·

Published

2026-04-21

·

Updated

2026-05-21

·

CVE-2026-33813

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description Parsing a WEBP image with an invalid, large size causes a panic on 32-bit platforms.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CLEANSTART-2026-RZ44006
CLEANSTART-2026-UY49411
CVE-2026-33813
GO-2026-4961
OPENSUSE-SU-2026:10682-1
RHSA-2026:7385
RHSA-2026:8291

Affected Products

Golang-Golang-X-Image
Golang.Org/X/Image
Golang.Org/X/Image/Webp
Image
Rclone