Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-82522

MEDIUM NVD
CVSS Score 5.4
Severity MEDIUM
Published Sep 02, 2026
Vendor unknown

Description

libjxl before 0.12 contains an integer underflow vulnerability in the container box parser that allows remote attackers to inject arbitrary metadata by exploiting 64-bit box size truncation to size_t on 32-bit platforms. Attackers can supply a crafted JPEG XL file causing the decoder to parse attacker-controlled codestream bytes as phantom box headers, enabling injection of arbitrary metadata (Exif, XMP, IPTC, JUMBF) and potential out-of-bounds reads.

References