{"id":"ECHO-07bd-5728-1ad8","upstream":["CVE-2021-36691"],"severity":[],"modified":"2026-07-20T09:20:35.224Z","affected":[{"package":{"ecosystem":"Echo","name":"jpeg-xl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.11.2-0.1~deb13u2+e1"}]}]}],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2021-36691"}],"withdrawn":"2026-07-20T09:20:35.224Z","summary":"Assertion failure (abort/DoS) in jxl::PlaneBase::PlaneBase() reachable only when\nthe cjxl encoder is used to encode a maliciously crafted GIF. There is no memory\ncorruption and no upstream fix: the upstream tracking issues (#422, #762) remain\nopen with no merged commit, and Debian rates the issue \"unimportant\" with a\n\"Negligible security impact\" note and no fixed version in any suite (bookworm\nthrough sid). With no upstream remediation available and negligible impact on the\nlibjxl decode path we ship, this is not actionable as a backport.\n"}