Vulnerability Report: GO-2026-4961
- CVE-2026-33813
- Affects: golang.org/x/image
- Published: Apr 21, 2026
Parsing a WEBP image with an invalid, large size panics on 32-bit platforms.
Affected Packages
-
PathVersionsSymbols
-
before v0.39.0
Aliases
References
Credits
- Tristan Madani
Feedback
See anything missing or incorrect?
Suggest an edit to this report.