CVE-2026-46599

The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data.
Configurations

No configuration.

History

No history.

Information

Published : 2026-05-29 20:16

Updated : 2026-07-22 06:10


NVD link : CVE-2026-46599

Mitre link : CVE-2026-46599

CVE.ORG link : CVE-2026-46599


JSON object : View

Products Affected

No product.

CWE
CWE-770

Allocation of Resources Without Limits or Throttling