Skip to content

fix(deps): update module golang.org/x/image to v0.41.0 [security]#1757

Open
oep-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/go-golang.org-x-image-vulnerability
Open

fix(deps): update module golang.org/x/image to v0.41.0 [security]#1757
oep-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/go-golang.org-x-image-vulnerability

Conversation

@oep-renovate
Copy link
Copy Markdown
Contributor

@oep-renovate oep-renovate Bot commented Mar 26, 2026

This PR contains the following updates:

Package Change Age Confidence
golang.org/x/image v0.18.0v0.41.0 age confidence

Go Images vulnerable to an out-of-memory error via a crafted TIFF file

CVE-2026-33809 / GHSA-44p7-9xx4-hf2g

More information

Details

A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.

Severity

  • CVSS Score: 5.3 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Go Images vulnerable to an out-of-memory error via a crafted TIFF file

CVE-2026-33809 / GHSA-44p7-9xx4-hf2g / GO-2026-4815

More information

Details

A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.

Severity

  • CVSS Score: 5.3 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


OOM from malicious IFD offset in golang.org/x/image/tiff

CVE-2026-33809 / GHSA-44p7-9xx4-hf2g / GO-2026-4815

More information

Details

A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.

Severity

Unknown

References

This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).


Panic when decoding large WEBP image on 32-bit platforms in golang.org/x/image

CVE-2026-33813 / GO-2026-4961

More information

Details

Parsing a WEBP image with an invalid, large size panics on 32-bit platforms.

Severity

Unknown

References

This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).


Excessive memory allocation when decoding malicious SFNT in golang.org/x/image

CVE-2026-33812 / GO-2026-4962

More information

Details

Parsing a malicious font file can cause excessive memory allocation.

Severity

Unknown

References

This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).


Panic when reading out of bound palette index in golang.org/x/image/bmp

CVE-2026-42500 / GO-2026-5031

More information

Details

Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image.

Severity

Unknown

References

This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).


Excessive resource consumption in PackBits decompression in golang.org/x/image/tiff

CVE-2026-46599 / GO-2026-5032

More information

Details

The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data.

Severity

Unknown

References

This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@oep-renovate
Copy link
Copy Markdown
Contributor Author

oep-renovate Bot commented Mar 26, 2026

ℹ️ Artifact update notice

File name: interactive_ai/services/media/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 1 additional dependency was updated
  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.24.0 -> 1.25.0
golang.org/x/text v0.32.0 -> v0.37.0

@oep-renovate oep-renovate Bot requested review from a team, jcchr, mgumowsk and piotrgrubicki as code owners March 26, 2026 03:17
@oep-renovate oep-renovate Bot force-pushed the renovate/go-golang.org-x-image-vulnerability branch from 4939046 to a1c765a Compare April 4, 2026 03:14
@oep-renovate oep-renovate Bot changed the title fix(deps): update module golang.org/x/image to v0.38.0 [security] fix(deps): update module golang.org/x/image to v0.38.0 [security] - autoclosed Apr 14, 2026
@oep-renovate oep-renovate Bot closed this Apr 14, 2026
@oep-renovate oep-renovate Bot deleted the renovate/go-golang.org-x-image-vulnerability branch April 14, 2026 03:16
@oep-renovate oep-renovate Bot changed the title fix(deps): update module golang.org/x/image to v0.38.0 [security] - autoclosed fix(deps): update module golang.org/x/image to v0.38.0 [security] Apr 17, 2026
@oep-renovate oep-renovate Bot reopened this Apr 17, 2026
@oep-renovate oep-renovate Bot force-pushed the renovate/go-golang.org-x-image-vulnerability branch 3 times, most recently from 922976e to 4e0314a Compare April 18, 2026 03:32
@oep-renovate oep-renovate Bot changed the title fix(deps): update module golang.org/x/image to v0.38.0 [security] fix(deps): update module golang.org/x/image to v0.39.0 [security] Apr 22, 2026
@oep-renovate oep-renovate Bot force-pushed the renovate/go-golang.org-x-image-vulnerability branch from 4e0314a to 9731f36 Compare April 22, 2026 03:33
@oep-renovate oep-renovate Bot force-pushed the renovate/go-golang.org-x-image-vulnerability branch 2 times, most recently from a16d2c6 to 99b6cd2 Compare May 1, 2026 03:35
@oep-renovate
Copy link
Copy Markdown
Contributor Author

oep-renovate Bot commented May 8, 2026

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@oep-renovate oep-renovate Bot force-pushed the renovate/go-golang.org-x-image-vulnerability branch 5 times, most recently from 7772977 to a9473f4 Compare May 15, 2026 03:36
@oep-renovate oep-renovate Bot force-pushed the renovate/go-golang.org-x-image-vulnerability branch from a9473f4 to b6c02db Compare May 22, 2026 03:37
Signed-off-by: oep-renovate[bot] <212772560+oep-renovate[bot]@users.noreply.github.com>
@oep-renovate oep-renovate Bot changed the title fix(deps): update module golang.org/x/image to v0.39.0 [security] fix(deps): update module golang.org/x/image to v0.41.0 [security] May 30, 2026
@oep-renovate oep-renovate Bot force-pushed the renovate/go-golang.org-x-image-vulnerability branch from b6c02db to 975c12d Compare May 30, 2026 03:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants