← Vulnerability feed

Vulnerability record · CVE-2026-1837 · published 11 February 2026

CVE-2026-1837: Libjxl project libjxl allocation without limits vulnerability

LLibjxl Project · Libjxl

A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninitialized unallocated region is copied to pixel data. This can be done by requesting color transformation of grayscale images to another grayscale color space. Buffers allocated for 1-float-per-pixel are used as if they are allocated for 3-float-per-pixel. That happens only if LCMS2 is used as CMS engine. There is another CMS engine available (selected by build flags).

8.7 CVSS 4.0 High EPSS 0.29% · top 81.0% CWE-805 · CWE-805CWE-770 · Allocation without limits
8.7CVSS 4.0 base score
0.29%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References, 2 tagged exploit
15 Jul 2026Last modified by NVD

Description

A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninitialized unallocated region is copied to pixel data. This can be done by requesting color transformation of grayscale images to another grayscale color space. Buffers allocated for 1-float-per-pixel are used as if they are allocated for 3-float-per-pixel. That happens only if LCMS2 is used as CMS engine. There is another CMS engine available (selected by build flags).

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-1837 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-27804Libjxl project libjxl out-of-bounds write vulnerabilityJPEG XL (aka jpeg-xl) through 0.3.2 allows writable memory corruption.EPSS 4.0%9.1CVE-2023-0645Libjxl project libjxl out-of-bounds read vulnerabilityAn out of bounds read exists in libjxl. An attacker using a specifically crafted file could cause an out of bounds read in the exif handler. We recom…EPSS 0.85%7.5CVE-2023-35790Libjxl project libjxl vulnerabilityAn issue was discovered in dec_patch_dictionary.cc in libjxl before 0.8.2. An integer underflow in patch decoding can lead to a denial of service, su…EPSS 0.77%7.5CVE-2021-36691Libjxl project libjxl vulnerabilitylibjxl v0.5.0 is affected by a Assertion failed issue in lib/jxl/image.cc jxl::PlaneBase::PlaneBase(). When encoding a malicous GIF file using cjxl, …EPSS 1.1%6.9CVE-2024-11403Libjxl project libjxl out-of-bounds read vulnerabilityThere exists an out of bounds read/write in LibJXL versions prior to commit 9cc451b91b74ba470fd72bd48c121e9f33d24c99. The JPEG decoder used by the JP…EPSS 0.63%6.9CVE-2024-11498Libjxl project libjxl uncontrolled resource consumption vulnerabilityThere exists a stack buffer overflow in libjxl. A specifically-crafted file can cause the JPEG XL decoder to use large amounts of stack space (up to …EPSS 0.60%6.5CVE-2022-34000Libjxl project libjxl vulnerabilitylibjxl 0.6.1 has an assertion failure in LowMemoryRenderPipeline::Init() in render_pipeline/low_memory_render_pipeline.cc.EPSS 0.89%6.5CVE-2021-36692Libjxl project libjxl divide by zero vulnerabilitylibjxl v0.3.7 is affected by a Divide By Zero in issue in lib/extras/codec_apng.cc jxl::DecodeImageAPNG(). When encoding a malicous APNG file using c…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2026-1837), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.