CVE-2023-0645: Libjxl Project Libjxl

Critical severity, CVSS 9.1. EPSS: 0.9% chance of exploitation in the next 30 days.

An out of bounds read exists in libjxl. An attacker using a specifically crafted file could cause an out of bounds read in the exif handler. We recommend upgrading to version 0.8.1 or past commit  https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159 https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159

Affected products

Published 2023-04-11. Last modified 2026-06-29.