CVE-2025-27795

ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.
Configurations

Configuration 1 (hide)

cpe:2.3:a:graphicsmagick:graphicsmagick:*:*:*:*:*:*:*:*

History

29 Jan 2026, 21:08

Type Values Removed Values Added
References () http://www.graphicsmagick.org/NEWS.html - () http://www.graphicsmagick.org/NEWS.html - Release Notes
References () https://foss.heptapod.net/graphicsmagick/graphicsmagick/-/commit/9bbae7314e3c3b19b830591010ed90bb136b9c42 - () https://foss.heptapod.net/graphicsmagick/graphicsmagick/-/commit/9bbae7314e3c3b19b830591010ed90bb136b9c42 - Patch
References () https://github.com/libjxl/libjxl/issues/3792#issuecomment-2330978387 - () https://github.com/libjxl/libjxl/issues/3792#issuecomment-2330978387 - Issue Tracking
References () https://github.com/libjxl/libjxl/issues/3793#issuecomment-2334843280 - () https://github.com/libjxl/libjxl/issues/3793#issuecomment-2334843280 - Issue Tracking
References () https://issues.oss-fuzz.com/issues/42536330#comment6 - () https://issues.oss-fuzz.com/issues/42536330#comment6 - Issue Tracking
First Time Graphicsmagick graphicsmagick
Graphicsmagick
CPE cpe:2.3:a:graphicsmagick:graphicsmagick:*:*:*:*:*:*:*:*
Summary
  • (es) ReadJXLImage en JXL en GraphicsMagick antes de 1.3.46 carece de los límites de recursos de dimensión de imagen.

07 Mar 2025, 16:15

Type Values Removed Values Added
Summary (en) JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits. (en) ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.
References
  • () https://foss.heptapod.net/graphicsmagick/graphicsmagick/-/commit/9bbae7314e3c3b19b830591010ed90bb136b9c42 -
  • () https://github.com/libjxl/libjxl/issues/3792#issuecomment-2330978387 -
  • () https://github.com/libjxl/libjxl/issues/3793#issuecomment-2334843280 -
  • () https://issues.oss-fuzz.com/issues/42536330#comment6 -

07 Mar 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-07 06:15

Updated : 2026-01-29 21:08


NVD link : CVE-2025-27795

Mitre link : CVE-2025-27795

CVE.ORG link : CVE-2025-27795


JSON object : View

Products Affected

graphicsmagick

  • graphicsmagick
CWE
CWE-770

Allocation of Resources Without Limits or Throttling