« Back to list

Golang

Golang Tiff: vulnerabilities and CVEs

Golang Tiff has 3 published vulnerabilities, 2 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs3
Last 12 months2
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-46604High (7.5)0.61%—Jun 26, 2026
The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset.
CVE-2026-33809Medium (5.3)0.39%—Mar 25, 2026
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.
CVE-2022-41727Medium (5.5)0.31%—Feb 28, 2023
An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. This could lead to a denial of service.

Other products by Golang