


Perceptive Security
SOC/SIEM Consultancy

Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function in file lib/extras/dec/pnm.cc.
Published:
26 mei 2026 om 22:00:00
Alert date:
27 mei 2026 om 20:13:41
Source:
nvd.nist.gov
Supply Chain & Dependencies
A heap buffer overflow vulnerability has been discovered in libjxl version 0.12.0. The vulnerability occurs in the jxl::extras::DecodeImagePNM function located in lib/extras/dec/pnm.cc when processing specially crafted PBM images. This memory corruption issue could potentially allow attackers to execute arbitrary code or cause denial of service by providing malicious PBM image files to applications using the affected libjxl library. The vulnerability has been reported through GitHub issues and pull requests, with proof-of-concept exploits available.
Technical details
Mitigation steps:
Affected products:
libjxl
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-70103
https://github.com/libjxl/libjxl/issues/4337
https://github.com/libjxl/libjxl/pull/4338
https://github.com/sigdevel/pocs/blob/main/res/libjxl/2025/2
https://infosec.exchange/@sigdevel/116642233929409910
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
