View all vulnerabilities

CVE-2024-24792

Panic when parsing invalid palette-color images in golang.org/x/image

Parsing a corrupt or malicious image with invalid color indices can cause a panic.

Patch Available

Fix available through Seal Security. No upgrade required, protect your application instantly.

Fix without upgrading
Vulnerability Details
Score
7.5
Score Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Versions
golang.org/x/image < 0.18.0
Severity
High
Ecosystem
GO
Publish Date
June 26, 2024
Modified Date
August 2, 2024