CVE-2026-33809
Aliases:GO-2026-4815GHSA-44p7-9xx4-hf2gDEBIAN-CVE-2026-33809CGA-2hr9-926c-qcw7CGA-3f3h-pxf7-4qw4CGA-4263-wwr2-45f7CGA-42mq-3rjv-hpwhCGA-4jgx-8vqf-6cw3CGA-4pv4-4j3p-c9c9CGA-55vf-jrvw-92wmCGA-5wgv-76hc-24fqCGA-6jw6-rcgj-m4v9CGA-6x8c-27x7-87hwCGA-76w3-pfv9-p2hhCGA-78cc-5g3j-jfxvCGA-84h2-qcjx-m5wqCGA-87pj-mg2v-cg92CGA-c4r9-vxff-9x95CGA-cj9h-8ww8-r9v7CGA-g223-cf9r-vp5qCGA-ghc2-3jmc-254fCGA-hrhh-x63v-p5fhCGA-j333-2r7c-472fCGA-jcv4-x9pj-g8w9CGA-jrmx-v6w6-35xvCGA-jw92-75rj-mcq5CGA-m99c-v7r2-wppcCGA-242x-hww7-6f4cCGA-28hw-64x4-pm52CGA-2m24-g47w-pvw6CGA-35gv-966h-f2hgCGA-35m3-9p3c-94j5CGA-3cp5-2xfg-r4rhCGA-3cx6-g8m7-hjf9CGA-3g75-6f8m-m25xCGA-3vw7-cvg7-c9m5CGA-3wqh-h6g5-h752CGA-3xcm-38mp-j4r4CGA-43pp-3j44-7vg9CGA-45r4-43vp-55wjCGA-47f2-f57x-h929CGA-4822-gqr9-pr94CGA-48wr-x9m4-hff9CGA-49m3-4g2p-4cp9CGA-4hw7-5v79-w4wmCGA-4jm7-8gq8-9293CGA-4r53-27rp-pg85CGA-4vw2-6xx4-6vv8CGA-4xhj-xfh3-j283CGA-52hc-jgc7-xq4xCGA-554h-5j8r-xc4wCGA-58rw-2j7q-fj9rCGA-5crm-rm2m-fh87CGA-5g7x-fx2x-xf89CGA-5mjx-3j6h-9p2qCGA-5qrr-h789-354gCGA-5vgx-v5h6-p4mxCGA-5vqw-f4c8-j6xjCGA-624m-5c87-3qhmCGA-64q2-r5j2-whxgCGA-65r2-gpq2-ggxvCGA-666m-xvjc-c29vCGA-673h-jhpx-mwj8CGA-67pp-w5g7-3vxwCGA-67w3-vjx2-34xjCGA-6f9g-hqj2-frhrCGA-6j9m-7hfm-q3vgCGA-6mwv-h5rm-mg24CGA-6p2c-6h3v-6px3CGA-6vpp-q425-4vfmCGA-6wh9-2x6v-vj33CGA-72xv-wvf3-4w3xCGA-77x2-x8xh-c4jvCGA-7f7r-xj5r-rcx6CGA-7w9r-q87f-qwx4CGA-82q8-9xvg-8534CGA-853x-95qg-r5gxCGA-894h-j39f-wgg4CGA-89qc-7fwm-r8pwCGA-8f9w-vgmw-35pqCGA-8h96-h3wm-82vgCGA-8p8g-xg2v-h755CGA-8q2v-wp79-jvw8CGA-8r22-3rf8-gx5vCGA-8vf3-qq88-9v26CGA-93fm-9wq3-f7xjCGA-9643-w46r-5v3hCGA-99jr-wrmf-qwq6CGA-9cx6-9cww-2mfcCGA-9rrv-cq3h-v8ffCGA-c2m2-24vg-2pm3CGA-c8rg-2974-6cmwCGA-c9c3-rmj4-pgq8CGA-cfmg-v593-8m7xCGA-cgpj-qr56-gx54CGA-chh9-xw2m-wx9pCGA-cvv3-vw29-fvvpCGA-cwcw-2mj6-f5p6CGA-cww3-j4pq-p4j5CGA-cx56-8gj2-cj6qCGA-f86j-vp9v-5jx3CGA-ffw5-f7hr-wqg4CGA-fhm7-f67c-265pCGA-fpfg-8v99-wg7mCGA-fqrj-63gw-55hjCGA-fwr3-w3h7-j5xrCGA-fx7m-v52j-3wmcCGA-g64j-9557-85pgCGA-g6mp-jj44-jr8hCGA-g7vc-9xgq-cv54CGA-g98q-2xxm-7mhvCGA-g9cq-gfc2-wj29CGA-gfmw-gfpr-q487CGA-ggjx-6p38-jhf6CGA-gj5q-4j3x-5757CGA-gmx4-jx69-8r5jCGA-gq79-7qw2-mmfqCGA-h2h5-pxxc-vrf6CGA-h5v8-78f4-3vmfCGA-h73g-5m7w-9f7rCGA-hc62-wwg3-r9crCGA-hch9-pc5w-2q94CGA-hpjq-6jx3-5j2fCGA-hrqr-r78q-rv2rCGA-hwfg-39jm-pg22CGA-hxg5-qh64-5238CGA-j4q5-cpfp-4mcvCGA-j622-j334-w82gCGA-j9v4-r8m7-pf29CGA-jh9g-c7m9-hvfxCGA-jhwx-3rvp-7gwhCGA-jjx7-hqqc-2hghCGA-jmwh-rm96-g6c7CGA-jx33-r3hp-v729CGA-m326-936w-rj2xCGA-m5xc-q9pf-9crxCGA-m82c-r4qx-7939CGA-m888-ccj2-57xqCGA-mgrg-mph7-97fmCGA-mhmf-559h-5xjfCGA-p58m-2hhp-pfh9CGA-p882-vwpq-vpg5CGA-p933-58w8-p4xrCGA-ph9c-3765-96qmCGA-pjq9-w94q-58xmCGA-pr5j-v6jp-fwvfCGA-q97c-xxp7-5896CGA-qcm6-c25m-fx4pCGA-qgcm-6hp9-q9jhCGA-qrcv-j2xp-rv25CGA-r46w-w6p4-8f5xCGA-rg7r-fpqx-wv2fCGA-rgw5-xrc5-x9cvCGA-rmjv-p42c-mxfrCGA-rv8w-fj22-gqx8CGA-rx3x-7c3h-x2xwCGA-v27m-8fv3-gxgxCGA-v39p-jjq9-758wCGA-v3gj-34w8-75qqCGA-v464-6768-gj6fCGA-v772-6pj7-pjc4CGA-v9g7-4p3p-4wh6CGA-vm77-qwf5-f9rcCGA-vp58-9j6p-59pvCGA-vp59-m7wq-77w8CGA-vrwc-cq74-cwcrCGA-vw28-7g62-p9jcCGA-vw5h-r556-8693CGA-vwf4-qghm-4q89CGA-vx8v-g3r8-4xpxCGA-vxpm-gm9h-x52fCGA-w384-9393-j8v4CGA-w78r-wvgq-vrm9CGA-wffq-qg6p-cq4hCGA-wghw-7pwc-3pwrCGA-whxq-vm3q-xjp8CGA-wq63-r5g6-8rwfCGA-wqmm-44f5-ghqxCGA-wrm7-63rh-73wjCGA-ww68-q4g2-48cxCGA-wxgr-ppg8-28mjCGA-x4cf-95r8-9jw5CGA-x799-8g89-4p94CGA-x7gc-cvwv-7469CGA-x8gw-2pf2-v34rCGA-xh76-v6xw-pgrjCGA-xp48-x7h8-jp36CGA-xqf5-mrhc-fq7wCGA-xqm2-23vf-w5cgCGA-xxr4-cwx6-7247CGA-xxvr-33q3-7v84CGA-xxx7-5mhf-f92j
Advisory lineage Upstream: 0 Downstream: 11
Analyzed
Published: 25 Mar 2026, 18:24
Last modified:06 Apr 2026, 21:12
Vulnerability Summary
Overall Risk (default)
low
21/100 CVSS Score
5.3 MEDIUM
v3.1 (cve.org)
EPSS Score
0.33% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
25 Mar 2026, 18:24
Published
Vulnerability first disclosed
06 Apr 2026, 21:12
Last Modified
Vulnerability information updated
Description
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Trends
Current EPSS score: 0.33%• Percentile: 26%
Techniques & Countermeasures
- CWE-434•Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Affected Systems
- chainguard•cg
< 0
- chainguard•chainctl
< 0
- chainguard•chainctl-fips
< 0
- chainguard•gatus
< 0
- chainguard•gatus-fips
< 0
- chainguard•gitea
< 0
- chainguard•gitea-fips
< 0
- chainguard•gitlab-workhorse-ce-18.1
all
- chainguard•gitlab-workhorse-ce-18.10
< 0
- chainguard•gitlab-workhorse-ce-18.11
< 0 | < 18.11.2-r3
- chainguard•gitlab-workhorse-ce-18.2
all
- chainguard•gitlab-workhorse-ce-18.3
all
- chainguard•gitlab-workhorse-ce-18.4
all
- chainguard•gitlab-workhorse-ce-18.5
all
- chainguard•gitlab-workhorse-ce-18.6
all
- chainguard•gitlab-workhorse-ce-18.7
all
- chainguard•gitlab-workhorse-ce-18.8
< 0
- chainguard•gitlab-workhorse-ce-18.9
< 0
- chainguard•gitlab-workhorse-ce-fips-18.1
all
- chainguard•gitlab-workhorse-ce-fips-18.10
< 0
- chainguard•gitlab-workhorse-ce-fips-18.11
< 0 | < 18.11.2-r3
- chainguard•gitlab-workhorse-ce-fips-18.2
all
- chainguard•gitlab-workhorse-ce-fips-18.3
all
- chainguard•gitlab-workhorse-ce-fips-18.4
all
- chainguard•gitlab-workhorse-ce-fips-18.5
all
- chainguard•gitlab-workhorse-ce-fips-18.6
all
- chainguard•gitlab-workhorse-ce-fips-18.7
all
- chainguard•gitlab-workhorse-ce-fips-18.8
< 0
- chainguard•gitlab-workhorse-ce-fips-18.9
< 0
- chainguard•glab
< 0
- chainguard•hugo
< 0.159.1-r1
- chainguard•hugo-extended
< 0.159.0-r1
- chainguard•hugo-fips
< 0.159.1-r1
- chainguard•kubescape
< 0
- chainguard•kubescape-server
< 0
- chainguard•kubescape-server-downloader
< 0
- chainguard•kubescape-server-fips
< 0
- chainguard•kubescape-server-fips-downloader
< 0
- chainguard•listmonk
< 6.0.0-r6
- chainguard•mailpit
< 1.29.4-r1
- chainguard•mailpit-fips
< 1.29.4-r1
- chainguard•mattermost-10.11
< 10.11.13-r3
- chainguard•mattermost-10.12
all
- chainguard•mattermost-11.0
all
- chainguard•mattermost-11.1
< 11.1.3-r5
- chainguard•mattermost-11.2
all
- chainguard•mattermost-11.4
< 11.4.3-r3
- chainguard•mattermost-11.5
< 11.5.1-r3
- chainguard•mattermost-fips-10.10
all
- chainguard•mattermost-fips-10.11
< 10.11.13-r3
Showing first 50 affected entries in server-rendered view.