CVE-2026-46602 affects multiple packages. The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption. See references for individual vulnerability details.