VDB
CVE-2025-70103
CVE-2025-70103
PUBLISHED
CVSS 7.3 HIGH
Reported by mitre · Published May 27, 2026
Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function in file lib/extras/dec/pnm.cc.
Risk Scores
CVSS 3.1
7.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | n/a, n/a |
Timeline
- May 27, 2026 CVE Published
- May 28, 2026 EPSS Score
- May 29, 2026 EPSS Score
- May 30, 2026 EPSS Score
- May 30, 2026 CVE Updated
- May 31, 2026 EPSS Score
- Jun 1, 2026 EPSS Score
- Jun 1, 2026 Security Advisory
- Jun 5, 2026 EPSS Score
- Jun 11, 2026 Coalition ESS Score
- Aug 7, 2026 EPSS Score
- Aug 30, 2026 EPSS Score