CVE detail
CVE-2026-1837
A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninitialized unallocated region is copied to pixel data. This can be done by requesting color transformation of grayscale images to another grayscale color space. Buffers allocated for 1-float-per-pixel are used as if they are allocated for 3-float-per-pixel. That happens only if LCMS2 is used as CMS engine. There is another CMS engine available (selected by build flags).
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 17.9 · diversity 18.0 · KEV 0.0 · OTX 0.0 · PoC 4.5
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
5 source links · newest first
- The Apple macOS Security Update ReviewZero Day Initiative
ation, we’re left to speculate on which of these bugs is the most severe. However, there are a couple that stand out. - CVE-2026-28819 (Wi-Fi) stands out as the strongest candidate for the most severe as it states, “An app may be able to execute arbitrary code with kernel privileges.” The combination of arbitrary code execution at the kernel level is a
vendorwww.thezdi.comMay 12, 2026, 12:21 PM - https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1837.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comFeb 11, 2026, 4:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2438974bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comFeb 11, 2026, 4:16 PM - https://access.redhat.com/security/cve/CVE-2026-1837access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 11, 2026, 4:16 PM No excerpt available.
Exploitgithub.comFeb 11, 2026, 4:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.90 · max 0 stars
- libjxl/libjxlHigh confidencegithubNVD Exploit reference0 starsDiscovered Jul 15, 2026, 3:18 AM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-53016CVSS 7.8 · High
In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - copy IV using skcipher ivsize AF_ALG rfc3686-ctr-aes-ccp requests pass an 8-byte IV to the driv…
- CVE-2026-31607CVSS 9.8 · Critical
In the Linux kernel, the following vulnerability has been resolved: usbip: validate number_of_packets in usbip_pack_ret_submit() When a USB/IP client receives a RET_SUBMIT respo…
- CVE-2026-27880CVSS 7.5 · High
The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes.
- CVE-2026-26955CVSS 8.8 · High
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a malicious RDP server can trigger a heap buffer overflow in FreeRDP clients using the GD…
- CVE-2025-23319CVSS 8.1 · High
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds write by sending a request. A s…
- CVE-2025-23318CVSS 8.1 · High
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds write. A successful exploit of…