CVE-2026-33812: Excessive memory allocation when decoding malicious SFNT in golang.org/x/image
Published Apr 21, 2026
·Updated
Parsing a malicious font file can cause excessive memory allocation.
Affected Software
2 affected components
go/golang.org/x/image
Golang Image Go<0.39.0
Remediation
Patch Available
Event History
Apr 21, 2026
CVE Published
via MITRE·07:21 PM
Data Sourced
via MITRE·07:21 PM
DescriptionWeakness
Data Sourced
via NVD·08:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-33812?
CVE-2026-33812 has been classified with a severity that indicates a potential risk of denial of service due to excessive memory allocation.
2
How do I fix CVE-2026-33812?
To fix CVE-2026-33812, upgrade to the latest version of golang.org/x/image which includes a patch for this vulnerability.
3
What type of attack is CVE-2026-33812 vulnerable to?
CVE-2026-33812 is vulnerable to denial of service attacks triggered by parsing malicious font files.
4
What version of golang.org/x/image is affected by CVE-2026-33812?
CVE-2026-33812 affects older versions of golang.org/x/image prior to the security patch implemented in subsequent releases.
5
What is the recommended response to CVE-2026-33812 for developers?
Developers should immediately review their use of the golang.org/x/image package and implement the latest security updates to mitigate CVE-2026-33812.