CVE-2023-36308: Disintegration Imaging
Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.
disintegration Imaging 1.6.2 allows attackers to cause a panic (because of an integer index out of range during a Grayscale call) via a crafted TIFF file to the scan function of scanner.go. NOTE: it is unclear whether there are common use cases in which this panic could have any security consequence
Affected products
- Disintegration Imaging: version 1.6.2 only
Published 2023-09-05. Last modified 2026-06-17.