Description
Problem
go.mod pins golang.org/x/image v0.30.0. govulncheck ./... reports three reachable vulnerabilities through user-controlled profile/project image decoding:
- GO-2026-5061: WebP alpha-channel size mismatch panic; fixed in v0.43.0.
- GO-2026-5031: BMP out-of-bounds palette index panic; fixed in v0.41.0.
- GO-2026-4961: large WebP decode panic on 32-bit platforms; fixed in v0.42.0.
The upload path accepts BMP and WebP (internal/server/profile_images.go:276-282) and calls both image.DecodeConfig and image.Decode on uploaded bytes (internal/server/profile_images.go:289-303). Profile and project images share this decoder.
Impact
A crafted image can panic a request handler. The global recoverer limits a single panic to a 500 response, but repeated uploads still provide an authenticated availability attack and exercise known-vulnerable parsing code. Open signup lowers the barrier to reaching the profile-image path.
Acceptance criteria
- Upgrade
golang.org/x/imageto v0.43.0 or newer compatible release and tidy the module graph. - Run
govulncheck ./...and confirm these vulnerabilities are no longer reachable. - Add malformed BMP/WebP regression fixtures covering both profile and project image uploads.
- Prove malformed images return a controlled 4xx response without a recovered panic or stored object.
- Keep the existing byte, dimension, and pixel-count limits intact.
Sub-issues
0Linked issues
0GitHub
0No branches or pull requests linked.
Comments
0No comments.