libjxl vulnerabilities
CVEs whose affected-version data names the libjxl package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-1837High· 7.5A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory
A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninitialized unallocated region is copied to pixel data. This can be done by requesting colo…
▾ Twilightlibjxl_project · libjxlEPSS 0.29%via NVD
CVE-2023-0645Medium· 5.3An out of bounds read exists in libjxl
An out of bounds read exists in libjxl. An attacker using a specifically crafted file could cause an out of bounds read in the exif handler. We recommend upgrading to version 0.8.1 or past commit https://github.com/libjxl/libjxl/pull/21…
▾ Sunlitlibjxl_project · libjxlEPSS 0.85%via NVD