PatchSiren

libjxl CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH libjxl CVE published 2026-07-17

CVE-2026-52584

A buffer overflow vulnerability exists in libjxl version 0.11.2 and earlier. The vulnerability is in the DecodeImageAPNG function and could allow a local attacker to obtain sensitive information. This vulnerability may impact users of libjxl in various environments, including web applications and image processing systems. The affected product is widely used for image compression and processing. Users shou [truncated]

HIGH libjxl CVE published 2026-05-27

CVE-2025-70103

A heap buffer overflow vulnerability exists in libjxl 0.12.0, triggered when processing crafted PBM images through the jxl::extras::DecodeImagePNM function in lib/extras/dec/pnm.cc. The vulnerability was published to CVE on 2026-05-27 and carries a HIGH severity CVSS 3.1 score of 7.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L). The issue was reported via GitHub issue and subsequently addressed through a pull re [truncated]