Skip to content

security: refuse raster images declaring more than 25 megapixels - #261

Merged
tannevaled merged 1 commit into
mainfrom
security-audit-r161
Oct 4, 2026
Merged

tannevaled merged 1 commit into
mainfrom
security-audit-r161

Conversation

@tannevaled

Copy link
Copy Markdown
Contributor

Security audit findings and one fix.

  • Decompression bomb: a 62KB PNG declaring 4000x4000 allocated 128MB on decode, measured. Raster decode now checks declared dimensions first and refuses above 25 megapixels. Test: fails with the guard disabled.
  • README now documents that the library does not guard SSRF (browserproxy does, at dial time).
  • Recorded for the owner: the Go toolchain pin (go1.26.4) misses six standard-library fixes shipped in go1.26.5 and 1.26.6; moving the pin changes CI.

🤖 Generated with Claude Code

A valid 62KB PNG declaring 4000x4000 allocated 128MB on decode, and page images
decode in parallel. decodeRaster now checks the declared size with
image.DecodeConfig before decoding. README documents that the library does not
guard SSRF; embedders need a dial guard (browserproxy has one).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@tannevaled
tannevaled merged commit 74a880b into main Oct 4, 2026
7 checks passed
@tannevaled
tannevaled deleted the security-audit-r161 branch October 4, 2026 17:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant