CVE-2026-46601
Description
The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size.
Metadata
Severity & Metrics
No CVSS data available.
Affected products (2)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| golang.org/x/image | golang.org/x/image/webp | — | 0 < 0.43.0 |
| golang.org/x/image | golang.org/x/image/webp | — | 0 < 0.43.0 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | CWE-125: Out-of-bounds Read |
References (3)