FR
live
High CVSS 7.3

CVE-2026-52834

NVD analysis in progress

jxl-oxide is a pure Rust implementation of a JPEG XL decoder. Prior to jxl-grid 0.6.2, decoding a crafted JPEG XL image on a 32-bit platform can overflow length calculations in AlignedGrid::with_alloc_tracker and related grid and subgrid arithmetic. A 65536 x 65536 frame can pass the frame-area limit while overflowing the usize element count, causing modular, VarDCT, or filter rendering paths to allocate a backing buffer smaller than the logical grid. A tiny bitstream-controlled cropped frame combined with a huge canvas or requested region can also reach the vulnerable composition path in crates/jxl-render/src/blend.rs through ordinary render_frame(). Later mutable subgrid and raw-pointer operations can then perform attacker-controlled out-of-bounds writes, causing memory corruption, denial of service, or arbitrary code execution. This issue is fixed in jxl-grid version 0.6.2.

What this means

Exposure
Exploitable with local access to the machine, without authentication and with no action from the victim. The attack does require particular conditions, which makes it less systematic.
Impact
An attacker can read some data, alter some data and take the service offline. The impact spreads beyond the vulnerable component into other parts of the system.
Weakness
A heap overflow corrupts allocator structures and can lead to code execution.
Likelihood
Its EPSS score stays low: nothing points to imminent exploitation, which is no reason to leave it unpatched.

What to doFold into the next patch cycle.

Read automatically from the CVSS vector, the weakness type (CWE) and the EPSS score. The technical description above remains the one published by NIST.

Published
19 August 2026
CVSS
7.3 (v3.1) CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H
EPSS
0.13% probability of exploitation within 30 days · above 3% of all CVEs
Weakness
CWE-122CWE-131CWE-190
Sources
nvd
References

Type at least two characters.

navigate open esc dismiss