What is CVE-2026-46603?
CVE-2026-46603 is a vulnerability in VP8L decoding within the `golang.org/x/image/vp8l` library. Decoding a crafted VP8L image containing many unused Huffman tree groups can trigger excessive memory allocation. A remote attacker can exploit this to cause a denial of service via memory exhaustion.
Azərbaycanca: CVE-2026-46603 `golang.org/x/image/vp8l` kitabxanasındakı VP8L dekodinqində aşkar edilmiş boşluqdur. Xüsusi hazırlanmış VP8L şəkil faylı çox sayda istifadəsiz Huffman ağacı qrupu ehtiva edərsə, həddindən artıq yaddaş ayrılmasına səbəb olur. Uzaqdan hücumçu bu zəiflikdən istifadə edərək yaddaş tükənməsi (memory exhaustion) yolu ilə xidmət əngəli (denial of service) yarada bilər.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
What can an attacker achieve by exploiting CVE-2026-46603?
An attacker can cause a denial of service by triggering excessive memory allocation through a crafted VP8L image file.
Under what condition does CVE-2026-46603 cause memory exhaustion?
Memory exhaustion occurs when decoding a crafted VP8L file containing many unused Huffman tree groups in the `golang.org/x/image/vp8l` library.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.