CVE-2026-46604: Panic decoding image with out-of-bounds strip offset in x/image/tiff in golang.org/x/image
Published Jun 26, 2026
·Updated
The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset.
Affected Software
2 affected components
golang.org/x/image/tiff
Golang Tiff Go<0.43.0
Remediation
Patch Available
Event History
Jun 26, 2026
CVE Published
via MITRE·08:22 PM
Data Sourced
via MITRE·08:22 PM
DescriptionWeakness
Data Sourced
via NVD·09:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-46604?
CVE-2026-46604 has a risk rating of 33.
2
How do I fix CVE-2026-46604?
To mitigate CVE-2026-46604, ensure that you are using the latest version of the golang.org/x/image/tiff package.
3
What causes the panic in CVE-2026-46604?
The panic occurs when decoding an invalid TIFF image that contains an out-of-bounds strip offset.
4
Which software is affected by CVE-2026-46604?
CVE-2026-46604 affects the TIFF decoder in the golang.org/x/image package.
5
When was CVE-2026-46604 published?
CVE-2026-46604 was published on June 26, 2026.