Skip to content

v0.11.2

Latest

Choose a tag to compare

@eustas eustas released this 10 Feb 14:18

Fixed

  • fix tile dimension in low memory rendering pipeline (#4495 -
    CVE-2025-12474)
  • fix number of channels for gray-to-gray color transform (#4579 -
    CVE-2026-1837)
  • djxl: reject decoding JXL files if "packed" representation size overflows
    size_t (#4589 - thanks to Mateusz Jurczyk of Google Project Zero for
    identifying this issue)

Note: This release is for evaluation purposes and may contain bugs, including security bugs, that may not be individually documented when fixed. See the SECURITY.md file for details. Always prefer to use the latest release.

Please provide feedback and report bugs here.