golang.org/x/image/bmp
- < v0.41.0
A vulnerability exists in the Golang package 'golang.org/x/image/bmp' prior to version 0.41.0, where decoding a paletted BMP file with an out-of-range palette index causes a panic when accessing pixels in the invalid image. This issue has been addressed in version 0.41.0, which now correctly returns an error instead of causing a panic.
The vulnerability leads to a panic, causing a runtime error that interrupts the program's execution.
Users can update to Golang 'golang.org/x/image' version 0.41.0 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.