SIGN IN SIGN UP

deps: update golang.org/x/image to v0.45.0 for CVE-2026-46603 (#11164)

golang.org/x/image v0.44.0 is affected by CVE-2026-46603 (GO-2026-6222):
a denial of service via excessive memory allocation when decoding
malformed VP8L (lossless WebP) data. It is fixed in v0.45.0, released
2026-08-11.

The decoder is reachable from SeaweedFS: weed/images/resizing.go
blank-imports golang.org/x/image/webp, which registers the VP8L decoder
with image.Decode, so the filer image resizing path decodes attacker
supplied WebP data with the affected version.

This is a go.mod/go.sum only change produced by
`go get golang.org/x/image@v0.45.0 && go mod tidy`; no other dependency
moved. `go build ./weed/`, `go vet ./weed/images/...`,
`go test ./weed/images/...` and `go mod verify` all pass.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
L
Lucas Frederico Roeder de Mello committed
98115ec2de1c1929c121073b3661e1ff39b4fcdc
Parent: a0b1272
Committed by GitHub <noreply@github.com> on 9/5/2026, 2:38:01 AM