Memory Corruption Vulnerability in jxl-oxide JPEG XL Decoder by Tirr-C
CVE-2026-52834

7.3HIGH

Key Information:

Vendor

Tirr-c

Vendor
CVE Published:
19 August 2026

What is CVE-2026-52834?

A vulnerability in the jxl-oxide JPEG XL decoder allows attackers to exploit crafted JPEG XL images on 32-bit systems, leading to potential out-of-bounds writes. This occurs due to improperly calculated lengths in AlignedGrid's allocation process, which may result in memory corruption or arbitrary code execution. The issue is addressed in jxl-grid version 0.6.2, and users are encouraged to upgrade to mitigate risks associated with this vulnerability.

Affected Version(s)

jxl-grid < 0.6.2

jxl-oxide < 0.12.6

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.