Vendorslibjxl Projectlibjxlany version
Vulnerabilities

libjxl Project libjxl any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2021-27804
JPEG XL (aka jpeg-xl) through 0.3.2 allows writable memory corruption.
Published 2021-03-02 · Modified
9.8EPSS 0.040
CVE-2024-11403
Out of Bounds Memory Read/Write in libjxl
Published 2024-11-25 · Analyzed
9.8EPSS 0.006
CVE-2023-0645
Out of Bounds read in libjxl
Published 2023-04-11 · Modified
9.1EPSS 0.009
CVE-2026-1837
libjxl: Out-of-bounds write in grayscale color transformation when using LCMS2
Published 2026-02-11 · Modified
8.8EPSS 0.003
CVE-2023-35790
An issue was discovered in dec_patch_dictionary.cc in libjxl before 0.8.2. An integer underflow in patch decoding can lead to a denial of service, such as an infinite loop.
Published 2023-06-16 · Modified
7.5EPSS 0.008
CVE-2024-11498
Resource exhaustion via Stack overflow in libjxl
Published 2024-11-25 · Analyzed
7.5EPSS 0.006
CVE-2021-45928
libjxl b02d6b9, as used in libvips 8.11 through 8.11.2 and other products, has an out-of-bounds write in jxl::ModularFrameDecoder::DecodeGroup (called from jxl::FrameDecoder::ProcessACGroup and jxl::ThreadPool::RunCallState<jxl::FrameDecoder::ProcessSections).
Published 2021-12-31 · Modified
5.5EPSS 0.004
CVE-2021-22564
Out of bounds Copy in Libjxl in large image groups
Published 2021-11-01 · Modified
5.5EPSS 0.003
CVE-2021-22563
Memory Overread in libjxl
Published 2021-11-01 · Modified
4.5EPSS 0.003
CVE-2025-12474
libjxl: Uninitialized memory read in decoder due to incorrect optimization in patch handling
Published 2026-02-11 · Analyzed
4.4EPSS 0.001