← Back

Tiff

tiff

Vendor: Golang • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Golang
1Tiff
Jul 1, 2026
Jun 26, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset.
1Golang
1Tiff
Jun 17, 2026
Mar 25, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.
2Fedoraproject
Golang
3Fedora
ImageTiff
Jun 17, 2026
Feb 28, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. This could lead to a denial of service.