VYPR

Libjxl

by Libjxl

Source repositories

CVEs (5)

  • CVE-2025-70103HigMay 27, 2026
    risk 0.40cvss 7.3epss

    Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function in file lib/extras/dec/pnm.cc.

  • CVE-2024-11403Nov 25, 2024
    risk 0.00cvss epss 0.00

    There exists an out of bounds read/write in LibJXL versions prior to commit 9cc451b91b74ba470fd72bd48c121e9f33d24c99. The JPEG decoder used by the JPEG XL encoder when doing JPEG recompression (i.e. if using JxlEncoderAddJPEGFrame on untrusted input) does not properly check…

  • CVE-2024-11498Nov 25, 2024
    risk 0.00cvss epss 0.00

    There exists a stack buffer overflow in libjxl. A specifically-crafted file can cause the JPEG XL decoder to use large amounts of stack space (up to 256mb is possible, maybe 512mb), potentially exhausting the stack. An attacker can craft a file that will cause excessive memory…

  • CVE-2023-0645Apr 11, 2023
    risk 0.00cvss epss 0.00

    An out of bounds read exists in libjxl. An attacker using a specifically crafted file could cause an out of bounds read in the exif handler. We recommend upgrading to version 0.8.1 or past commit  https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43f…

  • CVE-2022-34000Jun 19, 2022
    risk 0.00cvss epss 0.00

    libjxl 0.6.1 has an assertion failure in LowMemoryRenderPipeline::Init() in render_pipeline/low_memory_render_pipeline.cc.