CVE-2025-27795
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/03/2025
Last modified:
29/01/2026
Description
ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.
Impact
Base Score 3.x
4.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:graphicsmagick:graphicsmagick:*:*:*:*:*:*:*:* | 1.3.46 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.graphicsmagick.org/NEWS.html
- https://foss.heptapod.net/graphicsmagick/graphicsmagick/-/commit/9bbae7314e3c3b19b830591010ed90bb136b9c42
- https://github.com/libjxl/libjxl/issues/3792#issuecomment-2330978387
- https://github.com/libjxl/libjxl/issues/3793#issuecomment-2334843280
- https://issues.oss-fuzz.com/issues/42536330#comment6



