CVE-2026-33809
MediumAdvisory
Published 25 Mar 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.3
- base score, highest
- EPSS
- 0.003
- 26th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 104
- of 17,781 indexed, latest versions
- Container images
- 103
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Go Images vulnerable to an out-of-memory error via a crafted TIFF file
Carried by container images the latest versions of 104 of 17,781 indexed charts deploy, on 103 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang.org/ | v0.0.0-20190802002840-cff245a6509b, v0.0.0-20191009234506-e7c1f5e7dbb8, v0.0.0-20201208152932-35266b937fa6, v0.0.0-20210216034530-4410531fe030+34 more | 0.38.0 | 103 |
- OSV records
- GHSA-44p7-9xx4-hf2g
- Also known as
- GO-2026-4815
Charts affected
104 by stars
Container images carrying it
103 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| registry.gitlab.com/ | e0ab1fc86761 | golang.org/ | 0.38.0 | 1 |
| registry.gitlab.com/ | 9b9d1ed86b6a | golang.org/ | 0.38.0 | 1 |
| registry.gitlab.com/ | ed44d81a65de | golang.org/ | 0.38.0 | 1 |