Libjxl is a specialized image-codec library implementing the JPEG XL compression standard, and while its product footprint is narrow, the library sits in the codec layer of image-processing pipelines across browsers, media tools, and graphical applications. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated tendency toward critical severity, reflecting the memory-safety demands of image parsing and the inherent risk of untrusted image input. The exposure recurs consistently through out-of-bounds read and write conditions, reachable assertions, and resource-exhaustion weaknesses that are characteristic of codec implementations handling variable-length or malformed image data. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libjxl Project over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0645CRITICAL An out of bounds read exists in libjxl. An attacker using a specifically crafted file could cause an out of bounds read in the exif handler. We recommend upgrading to version 0.8.1 | Apr 11, 2023 | 9.1 | 32 | NO | NO |
CVE-2021-27804CRITICAL JPEG XL (aka jpeg-xl) through 0.3.2 allows writable memory corruption. | Mar 2, 2021 | 9.8 | 32 | NO | NO |
CVE-2024-11403CRITICAL There exists an out of bounds read/write in LibJXL versions prior to commit 9cc451b91b74ba470fd72bd48c121e9f33d24c99. The JPEG decoder used by the JPEG XL encoder when doing JPEG r | Nov 25, 2024 | 9.8 | 27 | NO | NO |
CVE-2026-1837HIGH A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninitialized unallocated region is c | Feb 11, 2026 | 7.5 | 24 | NO | NO |
CVE-2021-36691HIGH libjxl v0.5.0 is affected by a Assertion failed issue in lib/jxl/image.cc jxl::PlaneBase::PlaneBase(). When encoding a malicous GIF file using cjxl, an attacker can trigger a denia | Aug 30, 2021 | 7.5 | 24 | NO | NO |
CVE-2022-34000MEDIUM libjxl 0.6.1 has an assertion failure in LowMemoryRenderPipeline::Init() in render_pipeline/low_memory_render_pipeline.cc. | Jun 19, 2022 | 6.5 | 23 | NO | NO |
CVE-2024-11498HIGH There exists a stack buffer overflow in libjxl. A specifically-crafted file can cause the JPEG XL decoder to use large amounts of stack space (up to 256mb is possible, maybe 512mb) | Nov 25, 2024 | 7.5 | 22 | NO | NO |
CVE-2021-36692MEDIUM libjxl v0.3.7 is affected by a Divide By Zero in issue in lib/extras/codec_apng.cc jxl::DecodeImageAPNG(). When encoding a malicous APNG file using cjxl, an attacker can trigger a | Aug 30, 2021 | 6.5 | 22 | NO | NO |
CVE-2023-35790HIGH An issue was discovered in dec_patch_dictionary.cc in libjxl before 0.8.2. An integer underflow in patch decoding can lead to a denial of service, such as an infinite loop. | Jun 16, 2023 | 7.5 | 21 | NO | NO |
CVE-2021-45928MEDIUM libjxl b02d6b9, as used in libvips 8.11 through 8.11.2 and other products, has an out-of-bounds write in jxl::ModularFrameDecoder::DecodeGroup (called from jxl::FrameDecoder::Proce | Jan 1, 2022 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libjxl Project.
Media articles that mention a CVE ID that affects a product developed by Libjxl Project — matched by CVE ID, not by vendor name.