CVE Feed

    Dashboard / CVE / CVE-2026-1837

    CVE-2026-1837

    A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninitialized unallocated region is copied to pixel data. This can be done by requesting color transformation of grayscale images to another grayscale color space. Buffers allocated for 1-float-per-pixel are used as if they are allocated for 3-float-per-pixel. That happens only if LCMS2 is used as CMS engine. There is another CMS engine available (selected by build flags).

    Published:Feb 11, 2026
    Last Modified:Apr 17, 2026
    EPS:Feb 11, 2026
    EPSS Score:0.0003
    CVSS Score:7.5

    Affected Products

    Vendor
    Google
    Product
    Libjxl
    Vendor
    Libjxl Project
    Product
    Libjxl

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High