JLSEC-2026-1117

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2026/JLSEC-2026-1117.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1117.json
JSON Data
https://api.osv.dev/v1/vulns/JLSEC-2026-1117
Upstream
Published
2026-08-03T14:05:55.614Z
Modified
2026-08-03T14:15:04.821520789Z
Severity
  • 5.0 (Medium) CVSS_V2 - AV:N/AC:L/Au:N/C:N/I:N/A:P CVSS Calculator
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L CVSS Calculator
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

A weakness has been identified in LibRaw up to 0.22.0. This impacts the function HuffTable::initval of the file src/decompressors/losslessjpeg.cpp of the component JPEG DHT Parser. This manipulation of the argument bits[] causes out-of-bounds write. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 0.22.1 will fix this issue. Patch name: a6734e867b19d75367c05f872ac26322464e3995. It is advisable to upgrade the affected component.

Database specific
{
    "license": "CC-BY-4.0",
    "sources": [
        {
            "id": "CVE-2026-5318",
            "database_specific": {
                "status": "Analyzed"
            },
            "published": "2026-04-02T03:16:07.080Z",
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-5318",
            "html_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5318",
            "modified": "2026-06-17T10:58:48.457Z",
            "imported": "2026-08-03T13:28:43.514Z"
        }
    ]
}
References

Affected packages

Julia / LibRaw_jll

Package

Name
LibRaw_jll
Purl
pkg:julia/LibRaw_jll?uuid=d66ac3f3-933a-5ab8-8aa2-9e591b3c5af3

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.22.1+0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1117.json"