{"id":"CVE-2023-0645","title":"An out of bounds read exists in libjxl","summary":"An out of bounds read exists in libjxl. An attacker using a specifically crafted file could cause an out of bounds read in the exif handler. We recommend upgrading to version 0.8.1 or past commit  https://github.com/libjxl/libjxl/pull/21…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-125","CWE-125"],"vendor":"libjxl_project","product":"libjxl","affected":["libjxl < 0.8.1"],"patched":["libjxl 0.8.1"],"published":"2023-04-11","updated":"2026-06-29","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-0645","references":[{"url":"https://github.com/libjxl/libjxl/pull/2101","label":"cve-coordination@google.com"},{"url":"https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159","label":"cve-coordination@google.com"},{"url":"http://www.openwall.com/lists/oss-security/2026/06/29/3","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/libjxl/libjxl/pull/2101","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00854,"epssPercentile":0.56311,"ingestedAt":"2026-06-29T21:48:47.187Z","slug":"CVE-2023-0645","body":"## Overview\n\nAn out of bounds read exists in libjxl. An attacker using a specifically crafted file could cause an out of bounds read in the exif handler. We recommend upgrading to version 0.8.1 or past commit  https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159 https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159 \n\n## Affected\n\n- `libjxl < 0.8.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `libjxl 0.8.1`","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}