Parsing a WEBP image with an invalid, large size panics on 32-bit platforms.
References
| Link | Resource |
|---|---|
| https://go.dev/cl/759860 | Patch |
| https://go.dev/issue/78407 | Issue Tracking |
| https://pkg.go.dev/vuln/GO-2026-4961 | Vendor Advisory |
Configurations
History
13 May 2026, 15:51
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://go.dev/cl/759860 - Patch | |
| References | () https://go.dev/issue/78407 - Issue Tracking | |
| References | () https://pkg.go.dev/vuln/GO-2026-4961 - Vendor Advisory | |
| CWE | NVD-CWE-noinfo | |
| CPE | cpe:2.3:a:golang:image:*:*:*:*:*:go:*:* | |
| First Time |
Golang
Golang image |
22 Apr 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
21 Apr 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-21 20:16
Updated : 2026-05-13 15:51
NVD link : CVE-2026-33813
Mitre link : CVE-2026-33813
CVE.ORG link : CVE-2026-33813
JSON object : View
Products Affected
golang
- image
CWE
