CVE-2026-33813 is a denial-of-service vulnerability affecting WEBP image parsing functionality on 32-bit platforms, where processing specially crafted images with invalid large size parameters causes the application to panic and crash. The vulnerability has a CVSS score of 7.5 (HIGH) with a network-based attack vector requiring no privileges or user interaction, making it trivially exploitable by remote attackers. The impact is limited to availability, as successful exploitation results in service disruption through denial of service with no confidentiality or integrity compromise. Currently, there is no evidence of active exploitation in the wild, and the vulnerability is not tracked on the Known Exploited Vulnerabilities (KEV) catalog, indicating minimal real-world threat activity at this time. The FAUCET Risk Score of 38.0/100 and extremely low EPSS score suggest this vulnerability presents a below-average risk relative to other CVEs and warrants standard patching procedures rather than emergency response.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.39.0CPE matchmatch criteria | cpe:2.3:a:golang:image:*:*:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.