Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-1837— libjxl: Out-of-bounds write in grayscale color transformation when using LCMS2

Quick assessment

Affected
Google libjxl
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

libjxl是libjxl开源的一个 JPEG XL 图像格式参考实现。 libjxl存在安全漏洞,该漏洞源于解码器在处理特制文件时可能将像素数据写入未初始化的未分配内存,可能导致信息泄露。

AI Predicted 7.5 Difficulty: Easy EPSS 0.27% · P20

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
Google libjxl 0.9≤ 0.11.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-1837

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
libjxl: Out-of-bounds write in grayscale color transformation when using LCMS2
Source: CVE Program / CVE List V5
Vulnerability Description
A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninitialized unallocated region is copied to pixel data. This can be done by requesting color transformation of grayscale images to another grayscale color space. Buffers allocated for 1-float-per-pixel are used as if they are allocated for 3-float-per-pixel. That happens only if LCMS2 is used as CMS engine. There is another CMS engine available (selected by build flags).
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用不正确的长度值访问缓冲区
Source: CVE Program / CVE List V5
Vulnerability Title
libjxl 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
libjxl是libjxl开源的一个 JPEG XL 图像格式参考实现。 libjxl存在安全漏洞,该漏洞源于解码器在处理特制文件时可能将像素数据写入未初始化的未分配内存,可能导致信息泄露。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Google libjxl 0.9 ~ 0.11.1 -

II. Public POCs for CVE-2026-1837

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-1837

登录查看更多情报信息。

Proof of Concept for CVE-2026-1837 (1)

Same Patch Batch · Google · 2026-02-11 · 14 CVEs total

CVE-2026-1669 Arbitrary File Read in Keras via HDF5 External Datasets
CVE-2026-2323 Google Chrome 安全漏洞
CVE-2026-2322 Google Chrome 安全漏洞
CVE-2026-2320 Google Chrome 安全漏洞
CVE-2026-2321 Google Chrome 资源管理错误漏洞
CVE-2026-2318 Google Chrome 安全漏洞
CVE-2026-2319 Google Chrome 安全漏洞
CVE-2026-2317 Google Chrome 安全漏洞
CVE-2026-2316 Google Chrome 安全漏洞
CVE-2026-2315 Google Chrome 安全漏洞
CVE-2026-2314 Google Chrome 安全漏洞
CVE-2026-2313 Google Chrome 资源管理错误漏洞
CVE-2025-12474 libjxl: Uninitialized memory read in decoder due to incorrect optimization in patch handli

IV. Related Vulnerabilities

V. Comments for CVE-2026-1837

No comments yet


Leave a comment