Skip to content

[Aikido] Fix security issue in x/image via minor version upgrade from 0.43.0 to 0.45.0 - #317

Merged
chenxin0723 merged 1 commit into
masterfrom
fix/aikido-security-MAINT-1537-update-packages-89600682-tamz
Aug 18, 2026
Merged

[Aikido] Fix security issue in x/image via minor version upgrade from 0.43.0 to 0.45.0#317
chenxin0723 merged 1 commit into
masterfrom
fix/aikido-security-MAINT-1537-update-packages-89600682-tamz

Conversation

@aikido-autofix

Copy link
Copy Markdown
Contributor

Upgrade golang.org/x/image to fix HIGH severity DoS vulnerability in VP8L decoding that allows memory exhaustion attacks via crafted images.

✅ 1 CVE resolved by this upgrade

This PR will resolve the following CVEs:

Issue Severity           Description
CVE-2026-46603
HIGH
[golang.org/x/image] VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion.
🔗 Related Tasks

@chenxin0723
chenxin0723 merged commit d2c5622 into master Aug 18, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant