{"id":"CVE-2025-70103","title":"Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function in file lib/extras/dec/pnm.cc.","summary":"Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function in file lib/extras/dec/pnm.cc.","severity":"high","cvss":7.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","cwe":["CWE-122"],"published":"2026-05-27","updated":"2026-10-05","sourceUpdated":"2026-10-05T16:10:00.443","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-70103","references":[{"url":"https://github.com/libjxl/libjxl/issues/4337","label":"cve@mitre.org"},{"url":"https://github.com/libjxl/libjxl/pull/4338","label":"cve@mitre.org"},{"url":"https://github.com/sigdevel/pocs/blob/main/res/libjxl/2025/2","label":"cve@mitre.org"},{"url":"https://infosec.exchange/@sigdevel/116642233929409910","label":"cve@mitre.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/05/30/7","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/libjxl/libjxl/issues/4337","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd"],"epss":0.00367,"epssPercentile":0.28307,"ingestedAt":"2026-10-05T16:25:58.370Z","slug":"CVE-2025-70103","body":"## Overview\n\nHeap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function in file lib/extras/dec/pnm.cc.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":40.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}