Skip to content

Fix possible fix(deps): 2 vulnerable dependencies in go.mod - #2

Open
begininvoke wants to merge 1 commit into
sky-valley:mainfrom
begininvoke:redgem/security-fix-59d19b23
Open

Fix possible fix(deps): 2 vulnerable dependencies in go.mod#2
begininvoke wants to merge 1 commit into
sky-valley:mainfrom
begininvoke:redgem/security-fix-59d19b23

Conversation

@begininvoke

Copy link
Copy Markdown

Proposing a fix for something flagged in go.mod. It is around line 1.

The project uses golang.org/x/image v0.41.0, which contains a TIFF decoder flaw (CVE-2026-46602). The decoder fails to enforce a maximum tile size for tiled TIFF images, allowing an attacker to craft a malicious image that forces the decoder to allocate arbitrarily large buffers, leading to unbounded memory consumption and possible denial‑of‑service. Because this can be triggered simply by processing untrusted image data, the risk is high. Upgrading to a version where the decoder enforces proper limits (v0.43.0) eliminates the vulnerability.

Update go.mod to use the fixed versions of the vulnerable dependencies.

For reference: rule CVE-2026-46602. Rated high.

Take or leave whichever parts are useful. If this is not the right approach, closing is fine.


Found with automated scanning (RedGem) and reviewed before opening. If it is not useful, closing it is completely fine.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant