CVE-2026-1837 describes a critical vulnerability in libjxl's decoder, where a specially crafted file can lead to memory corruption by writing pixel data to uninitialized memory regions. This flaw specifically impacts grayscale image transformations when the LCMS2 CMS engine is in use, causing single-float-per-pixel buffers to be treated as three-float-per-pixel. With a CVSS score of 8.7 (HIGH) and a FAUCET Risk Score of 93/100, this vulnerability presents a significant risk, allowing unauthenticated attackers to trigger severe impacts on confidentiality, integrity, and availability through user interaction. While there is no evidence of active exploitation, public exploit code, or Metasploit/Nuclei modules, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.9.0, <= 0.11.1CPE matchmatch criteria | cpe:2.3:a:libjxl_project:libjxl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
libjxl vulnerability
Apr 2, 2026libjxl: libjxl: Out-of-bounds write in grayscale color transformation when using LCMS2
Feb 11, 2026About the security content of tvOS 26.5 - Apple Support
About the security content of watchOS 26.5 - Apple Support
About the security content of visionOS 26.5 - Apple Support
About the security content of macOS Tahoe 26.5 - Apple Support
About the security content of iOS 26.5 and iPadOS 26.5 - Apple Support