JLSEC-2026-125

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2026/JLSEC-2026-125.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-125.json
JSON Data
https://api.osv.dev/v1/vulns/JLSEC-2026-125
Upstream
  • EUVD-2025-15404
  • GHSA-f6x7-5x3c-j3rg
Published
2026-04-17T13:07:52.234Z
Modified
2026-04-17T13:32:00.424678086Z
Severity
  • 4.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L CVSS Calculator
Summary
In libavif before 1.3.0, makeRoom in stream.c has an integer overflow and resultant buffer...
Details

In libavif before 1.3.0, makeRoom in stream.c has an integer overflow and resultant buffer overflow in stream->offset+size.

Database specific
{
    "sources": [
        {
            "database_specific": {
                "status": "Modified"
            },
            "modified": "2025-11-03T20:19:05.993Z",
            "id": "CVE-2025-48174",
            "published": "2025-05-16T05:15:37.213Z",
            "imported": "2026-04-17T08:45:49.614Z",
            "html_url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48174",
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-48174"
        },
        {
            "modified": "2025-11-03T21:34:58Z",
            "url": "https://api.github.com/advisories/GHSA-f6x7-5x3c-j3rg",
            "id": "GHSA-f6x7-5x3c-j3rg",
            "published": "2025-05-16T06:30:24Z",
            "imported": "2026-04-17T08:45:50.076Z",
            "html_url": "https://github.com/advisories/GHSA-f6x7-5x3c-j3rg"
        },
        {
            "modified": "2025-11-03T20:04:42Z",
            "url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2025-15404",
            "id": "EUVD-2025-15404",
            "published": "2025-05-16T00:00:00Z",
            "imported": "2026-04-17T08:45:49.736Z",
            "html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-15404"
        }
    ],
    "license": "CC-BY-4.0"
}
References

Affected packages

Julia / libavif_jll

Package

Name
libavif_jll
Purl
pkg:julia/libavif_jll?uuid=d7a461ab-9c30-58dd-b115-285ac81dc4e5

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.0+0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-125.json"