CVE-2026-33809 describes a vulnerability in golang.org/x/image/tiff where a maliciously crafted TIFF file can trigger an attempt to allocate up to 4GiB of memory. Rated Medium (CVSS 5.3), this can be exploited remotely without authentication or user interaction, leading to excessive resource consumption or an out-of-memory error. There is currently no evidence of active exploitation, public exploit code, or significant media coverage, though it has received minor community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.38.0CPE matchmatch criteria | cpe:2.3:a:golang:tiff:*:*:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.