CVE-2026-1837

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
11/02/2026
Last modified:
11/02/2026

Description

A specially-crafted file can cause libjxl&amp;#39;s decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninitialized unallocated region is copied to pixel data.<br /> <br /> This can be done by requesting color transformation of grayscale images to another grayscale color space. Buffers allocated for 1-float-per-pixel are used as if they are allocated for 3-float-per-pixel. That happens only if LCMS2 is used as CMS engine. There is another CMS engine available (selected by build flags).