CVE-2025-27795
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.3epss 0.4%
exploitation probability
0.4%top 62% of all CVEs
observed exploitation
nono source reports it
ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
Affected products
GraphicsMagick · GraphicsMagickReferences
https://foss.heptapod.net/graphicsmagick/graphicsmagick/-/commit/9bbae7314e3c3b19b830591010ed90bb136b9c42https://github.com/libjxl/libjxl/issues/3792#issuecomment-2330978387https://github.com/libjxl/libjxl/issues/3793#issuecomment-2334843280https://issues.oss-fuzz.com/issues/42536330#comment6http://www.graphicsmagick.org/NEWS.html