JLSEC-2026-493 Medium 4.3
JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.
ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.
References
- http://www.graphicsmagick.org/NEWS.html
- https://foss.heptapod.net/graphicsmagick/graphicsmagick/-/commit/9bbae7314e3c3b19b830591010ed90bb136b9c42
- https://github.com/advisories/GHSA-69r2-5wxm-3hf6
- https://github.com/libjxl/libjxl/issues/3792#issuecomment-2330978387
- https://github.com/libjxl/libjxl/issues/3793#issuecomment-2334843280
- https://issues.oss-fuzz.com/issues/42536330#comment6
- https://nvd.nist.gov/vuln/detail/CVE-2025-27795