« Volver al listado

CVE-2026-42500

Estado: AplazadaMedia (5.3)—

Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-42500",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-42500",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-29T19:51:07.816824Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@golang.org",
      "affectedData": [
        {
          "vendor": "golang.org/x/image",
          "product": "golang.org/x/image/bmp",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "0.41.0",
              "versionType": "semver"
            }
          ],
          "packageName": "golang.org/x/image/bmp",
          "collectionURL": "https://pkg.go.dev",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "decodePaletted"
            },
            {
              "name": "Decode"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-05-29T20:16:23.627",
  "references": [
    {
      "url": "https://go.dev/cl/781500",
      "source": "security@golang.org"
    },
    {
      "url": "https://go.dev/issue/79576",
      "source": "security@golang.org"
    },
    {
      "url": "https://groups.google.com/g/golang-announce/c/uhYX90BlBvI",
      "source": "security@golang.org"
    },
    {
      "url": "https://pkg.go.dev/vuln/GO-2026-5031",
      "source": "security@golang.org"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image."
    },
    {
      "lang": "es",
      "value": "Decodificación de un archivo BMP paletizado con un índice de paleta fuera de rango resulta en un pánico al acceder a los píxeles en la imagen inválida."
    }
  ],
  "lastModified": "2026-07-22T06:10:00.170",
  "sourceIdentifier": "security@golang.org"
}