GHSA-2v8p-fqpx-2q3w

Suggest an improvement
Source
https://github.com/advisories/GHSA-2v8p-fqpx-2q3w
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-2v8p-fqpx-2q3w/GHSA-2v8p-fqpx-2q3w.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-2v8p-fqpx-2q3w
Published
2026-07-02T20:44:57Z
Modified
2026-07-02T21:00:18Z
Severity
  • 6.2 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
jxl-oxide: integer subtraction overflow panic in cluster_from_table via crafted JXL input (DoS)
Details

Summary

Logic bug in decode_simple_table_slow may cause integer arithmetic overflow when decoding Modular image with certain kind of MA tree, which may panic with overflow-checks enabled.

Impact

Denial of service: any application passing untrusted JXL data to JxlImage::render_frame (or equivalent) can be crashed. Affects all builds with overflow checks enabled, which includes debug builds and any release build that sets overflow-checks = true in Cargo.toml or [profile.*].

No memory corruption is possible — the panic fires before any unsafe code is reached.

Database specific
{
    "cwe_ids":  [
        "CWE-190"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-02T20:44:57Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

crates.io / jxl-modular

Package

Name
jxl-modular
View open source insights on deps.dev
Purl
pkg:cargo/jxl-modular

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.11.3

Database specific

last_known_affected_version_range
"<= 0.11.2"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-2v8p-fqpx-2q3w/GHSA-2v8p-fqpx-2q3w.json"