CVE Vulnerabilities

CVE-2026-33813

Published: Apr 21, 2026 | Modified: May 13, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Parsing a WEBP image with an invalid, large size panics on 32-bit platforms.

Affected Software

NameVendorStart VersionEnd Version
ImageGolang*0.39.0 (excluding)
Cryostat 4 on RHEL 9RedHatcryostat/cryostat-storage-rhel9:4.2.0-13*
Multicluster Global Hub 1.4.5RedHatmulticluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439*
Multicluster Global Hub 1.5.4RedHatmulticluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753*
Multicluster Global Hub 1.6.2RedHatmulticluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118*
Multicluster Global Hub 1.7.1RedHatmulticluster-globalhub/multicluster-globalhub-grafana-rhel9:1779925273*
Red Hat Hardened ImagesRedHatgolang1-25-main-1.25.9-1.hum1*
Red Hat Hardened ImagesRedHatgolang1-26-main-1.26.2-1.1.hum1*
Golang-golang-x-imageUbuntuupstream*

References