CVE-2026-46604Disclosure(golang / tiff)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tiff

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
tiff

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-27: 3Technical Details · 2026-06-27: 306-27
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-46604 TIFF Decoder Panic from Out-of-Bounds Strip Offset in Invalid Images https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-46604

    Post summary

    The post references CVE‑2026‑46604 with a brief description of an out‑of‑bounds TIFF decoder issue, but it does not include a PoC, exploit, or mitigation advice.

    00010158
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-46604 The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset. https://www.cve.org/CVERecord?id=CVE-2026-46604 ----- Traducción: CVE-2026-46604 El decodificador TIFF puede bloquearse al decodificar una imagen inválida con … http://infoflow.cloud`

    Post summary

    The text announces CVE‑2026‑46604 as a TIFF decoder vulnerability that causes a panic on decoding invalid images with out‑of‑bounds strip offsets, but does not provide PoC, exploit code, patch or evidence of active attack.

    0001045
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-46604 The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset. https://www.cve.org/CVERecord?id=CVE-2026-46604

    Post summary

    The statement announces CVE-2026-46604, noting a TIFF decoder panic from an out‑of‑bounds strip offset, with no PoC, exploit, or patch information provided.

    00010888
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgolangtiff-go-

Explore more