MEDIUM
GHSA-fmhh-rw3h-785m
bep/imagemeta allows a potentially large memory allocation in PNG and WebP parsing
Quick fix
GHSA-fmhh-rw3h-785m — github.com/bep/imagemeta: upgrade to the fixed version with the command below.
go get github.com/bep/imagemeta@v0.11.0Details
### Impact
The buffer created for parsing metadata for PNG and WebP images was only bounded by their input data type, which could lead to potentially large memory allocation, and unreasonably high for image metadata. Before `v0.11.0`, If you didn't trust the input images, this could be abused to construct denial-of-service attacks.
### Patches
`v0.11.0` added a 10 MB upper limit.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/bep/imagemeta
Introduced in:
0Fixed in: 0.11.0Fix
go get github.com/bep/imagemeta@v0.11.0