
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33809 is a Denial of Service vulnerability in the golang.org/x/image/tiff Go package that allows a remote, unauthenticated attacker to trigger excessive memory allocation via a maliciously crafted TIFF file. The flaw affects all versions of golang.org/x/image/tiff prior to 0.38.0. It was published on March 25, 2026, and assigned a CVSS v3.1 base score of 5.3 (Medium) (Red Hat Advisory, Red Hat Bugzilla).
The root cause is improper validation of specified index, position, or offset values within TIFF file metadata during image decoding (CWE-1285), combined with insufficient restrictions on file type handling (CWE-434). When a specially crafted TIFF file is processed, the decoder reads attacker-controlled values (such as image dimensions or strip/tile offsets) without adequate bounds checking, causing it to attempt memory allocations of up to 4 GiB. The attack requires no authentication and can be triggered remotely by supplying a malicious TIFF file to any application that uses the vulnerable library for image decoding (Red Hat Bugzilla, Go Vulnerability DB).
Successful exploitation causes the affected application to attempt allocating up to 4 GiB of memory during TIFF decoding, resulting in severe resource exhaustion or an out-of-memory (OOM) error that crashes the process. This leads to a Denial of Service (DoS) condition, rendering the affected service unavailable to legitimate users. The impact is limited to availability; there is no evidence of confidentiality or integrity compromise beyond what the CVSS score reflects (Red Hat Advisory, Go Vulnerability DB).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Red Hat Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.027%, indicating a low probability of exploitation in the near term. The attack requires no authentication and has low complexity, making it straightforward to attempt if a PoC were to emerge (Go Vulnerability DB).
golang.org/x/image/tiff package at a version prior to 0.38.0 (e.g., image upload endpoints, media servers such as Navidrome, or file sync tools such as rclone).golang.org/x/image/tiff; sudden process restarts of image-processing services.dmesg or /var/log/syslog) referencing the affected service.The primary remediation is to upgrade the golang.org/x/image/tiff dependency to version 0.38.0 or later, which contains the fix (Go Vulnerability DB, Red Hat Bugzilla). Applications such as Navidrome (v0.61.0+) and rclone have already released updates incorporating the patched library. As interim workarounds, implement input validation and file-type filtering at network entry points to reject malformed or oversized TIFF files before they reach the decoder, and apply resource quotas (e.g., memory limits via cgroups or container resource constraints) to image-processing services to limit the blast radius of a memory exhaustion attack (Red Hat Advisory).
Red Hat tracked the vulnerability via Bugzilla and assigned it medium severity, with product security teams monitoring affected packages (Red Hat Bugzilla). openSUSE issued multiple security announcements addressing the vulnerability in their package ecosystem (openSUSE Security). The Navidrome media server community discussed the fix in the context of the v0.61.0 release on Reddit, and rclone included the patched library in a changelog update, indicating broad downstream awareness among Go ecosystem maintainers.
Fix availability across major Linux distributions and their releases.
bookworm
golang-golang-x-image
sid
golang-golang-x-image: 0.38.0-1
trixie
golang-golang-x-image
bionic (esm-apps)
golang-golang-x-image
devel
golang-golang-x-image
focal (esm-apps)
golang-golang-x-image
jammy
golang-golang-x-image
jammy (esm-apps)
golang-golang-x-image
noble
golang-golang-x-image
noble (esm-apps)
golang-golang-x-image
resolute
golang-golang-x-image
OpenShift
openshift4/ose-tests-rhel9
RHEL 8
go-toolset:rhel8/golang.src
RHEL 9
golang.src
RHEL 10
golang.src
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."