The Jpeg vendor maintains a focused set of image-compression libraries, most notably libjpeg and JPEG-XL, that are embedded widely across media processing pipelines, browsers, and imaging applications despite a narrow product scope. Its vulnerability profile concentrates on memory-safety and control-flow weaknesses—NULL pointer dereferences, out-of-bounds writes, buffer-boundary violations, infinite loops, and reachable assertions—that are characteristic of C-based image decoding and codec implementations. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jpeg over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-37768HIGH libjpeg commit 281daa9 was discovered to contain an infinite loop via the component Frame::ParseTrailer. | Aug 18, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-28026HIGH jpeg-xl v0.3.2 is affected by a heap buffer overflow in /lib/jxl/coeff_order.cc ReadPermutation. When decoding a malicous jxl file using djxl, an attacker can trigger arbitrary cod | Mar 5, 2021 | 7.8 | 24 | NO | NO |
CVE-2022-37770MEDIUM libjpeg commit 281daa9 was discovered to contain a segmentation fault via LineMerger::GetNextLowpassLine at linemerger.cpp. This vulnerability allows attackers to cause a Denial of | Aug 18, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-32978MEDIUM There is an assertion failure in SingleComponentLSScan::ParseMCU in singlecomponentlsscan.cpp in libjpeg before 1.64 via an empty JPEG-LS scan. | Jun 10, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-37769MEDIUM libjpeg commit 281daa9 was discovered to contain a segmentation fault via HuffmanDecoder::Get at huffmandecoder.hpp. This vulnerability allows attackers to cause a Denial of Servic | Aug 18, 2022 | 6.5 | 22 | NO | NO |
CVE-2022-31796MEDIUM libjpeg 1.63 has a heap-based buffer over-read in HierarchicalBitmapRequester::FetchRegion in hierarchicalbitmaprequester.cpp because the MCU size can be different between allocati | Jun 2, 2022 | 6.5 | 22 | NO | NO |
CVE-2021-39520MEDIUM An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function BlockBitmapRequester::PushReconstructedData() located in blockbitmaprequester. | Sep 20, 2021 | 6.5 | 22 | NO | NO |
CVE-2022-35166MEDIUM libjpeg commit 842c7ba was discovered to contain an infinite loop via the component JPEG::ReadInternal. | Aug 18, 2022 | 5.5 | 21 | NO | NO |
CVE-2021-39519MEDIUM An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function BlockBitmapRequester::PullQData() located in blockbitmaprequester.cpp It allow | Sep 20, 2021 | 6.5 | 21 | NO | NO |
CVE-2021-39518MEDIUM An issue was discovered in libjpeg through 2020021. LineBuffer::FetchRegion() in linebuffer.cpp has a heap-based buffer overflow. | Sep 20, 2021 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jpeg.
Media articles that mention a CVE ID that affects a product developed by Jpeg — matched by CVE ID, not by vendor name.