trackslash
TRACK-7 P1

Upgrade x/image to remediate reachable image-decoder vulnerabilities

0
All issues

Description

Problem

go.mod pins golang.org/x/image v0.30.0. govulncheck ./... reports three reachable vulnerabilities through user-controlled profile/project image decoding:

  • GO-2026-5061: WebP alpha-channel size mismatch panic; fixed in v0.43.0.
  • GO-2026-5031: BMP out-of-bounds palette index panic; fixed in v0.41.0.
  • GO-2026-4961: large WebP decode panic on 32-bit platforms; fixed in v0.42.0.

The upload path accepts BMP and WebP (internal/server/profile_images.go:276-282) and calls both image.DecodeConfig and image.Decode on uploaded bytes (internal/server/profile_images.go:289-303). Profile and project images share this decoder.

Impact

A crafted image can panic a request handler. The global recoverer limits a single panic to a 500 response, but repeated uploads still provide an authenticated availability attack and exercise known-vulnerable parsing code. Open signup lowers the barrier to reaching the profile-image path.

Acceptance criteria

  • Upgrade golang.org/x/image to v0.43.0 or newer compatible release and tidy the module graph.
  • Run govulncheck ./... and confirm these vulnerabilities are no longer reachable.
  • Add malformed BMP/WebP regression fixtures covering both profile and project image uploads.
  • Prove malformed images return a controlled 4xx response without a recovered panic or stored object.
  • Keep the existing byte, dimension, and pixel-count limits intact.

Sub-issues

0

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

0
No comments.