{"id":"CVE-2026-46603","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-46603","summary":"Excessive memory allocation during VP8L decoding in golang.org/x/image","details":"VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion.","published":"2026-08-14T16:22:50Z","modified":"2026-08-14T16:45:12.487565504Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Go","name":"golang.org/x/image","fixedVersion":"0.45.0"}],"fix":null,"references":[{"type":"REPORT","url":"https://go.dev/issue/80069"},{"type":"FIX","url":"https://go.dev/cl/793460"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-14T16:45:12.487565504Z"}}