← Vulnerability feed

Vulnerability record · CVE-2023-0645 · published 11 April 2023

CVE-2023-0645: Libjxl project libjxl out-of-bounds read vulnerability

LLibjxl Project · Libjxl

An out of bounds read exists in libjxl. An attacker using a specifically crafted file could cause an out of bounds read in the exif handler. We recommend upgrading to version 0.8.1 or past commit  https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159 https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159

9.1 CVSS 3.1 Critical EPSS 0.85% · top 43.3% CWE-125 · Out-of-bounds read
9.1CVSS 3.1 base score
0.85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References
29 Jun 2026Last modified by NVD

Description

An out of bounds read exists in libjxl. An attacker using a specifically crafted file could cause an out of bounds read in the exif handler. We recommend upgrading to version 0.8.1 or past commit  https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159 https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-0645 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-27804Libjxl project libjxl out-of-bounds write vulnerabilityJPEG XL (aka jpeg-xl) through 0.3.2 allows writable memory corruption.EPSS 4.0%8.7CVE-2026-1837Libjxl project libjxl allocation without limits vulnerabilityA specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninit…EPSS 0.29%7.5CVE-2023-35790Libjxl project libjxl vulnerabilityAn issue was discovered in dec_patch_dictionary.cc in libjxl before 0.8.2. An integer underflow in patch decoding can lead to a denial of service, su…EPSS 0.77%7.5CVE-2021-36691Libjxl project libjxl vulnerabilitylibjxl v0.5.0 is affected by a Assertion failed issue in lib/jxl/image.cc jxl::PlaneBase::PlaneBase(). When encoding a malicous GIF file using cjxl, …EPSS 1.1%6.9CVE-2024-11403Libjxl project libjxl out-of-bounds read vulnerabilityThere exists an out of bounds read/write in LibJXL versions prior to commit 9cc451b91b74ba470fd72bd48c121e9f33d24c99. The JPEG decoder used by the JP…EPSS 0.63%6.9CVE-2024-11498Libjxl project libjxl uncontrolled resource consumption vulnerabilityThere exists a stack buffer overflow in libjxl. A specifically-crafted file can cause the JPEG XL decoder to use large amounts of stack space (up to …EPSS 0.60%6.5CVE-2022-34000Libjxl project libjxl vulnerabilitylibjxl 0.6.1 has an assertion failure in LowMemoryRenderPipeline::Init() in render_pipeline/low_memory_render_pipeline.cc.EPSS 0.89%6.5CVE-2021-36692Libjxl project libjxl divide by zero vulnerabilitylibjxl v0.3.7 is affected by a Divide By Zero in issue in lib/extras/codec_apng.cc jxl::DecodeImageAPNG(). When encoding a malicous APNG file using c…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2023-0645), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.