Medium severity4.4NVD Advisory· Published Feb 11, 2026· Updated Apr 24, 2026
CVE-2025-12474
CVE-2025-12474
Description
A specially-crafted file can cause libjxl's decoder to read pixel data from uninitialized (but allocated) memory.
This can be done by causing the decoder to reference an outside-image-bound area in a subsequent patches. An incorrect optimization causes the decoder to omit populating those areas.
Affected products
1Patches
14523cf652f56https://github.com/libjxl/libjxlvia nvd-ref
Vulnerability mechanics
Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
1- github.com/libjxl/libjxl/pull/4495nvdIssue TrackingPatch
News mentions
0No linked articles in our index yet.