CVE-2025-8835
Last modified
CVE-2025-8835 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. A vulnerability was found in JasPer up to 4.2.5. Affected by this vulnerability is the function jas_image_chclrspc of the file src/libjasper/base/jas_image.c of the component Image Color Space Conversion Handler. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
A vulnerability was found in JasPer up to 4.2.5. Affected by this vulnerability is the function jas_image_chclrspc of the file src/libjasper/base/jas_image.c of the component Image Color Space Conversion Handler. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The identifier of the patch is bb7d62bd0a2a8e0e1fdb4d603f3305f955158c52. It is recommended to apply a patch to fix this issue.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jasper Project | Jasper | <= 4.2.5 |
References
- https://github.com/jasper-software/jasper/issues/400Exploit, Issue Tracking, Vendor Advisory
- https://github.com/jasper-software/jasper/issues/400#issuecomment-3134702772Exploit, Issue Tracking, Vendor Advisory
- https://vuldb.com/?ctiid.319369Permissions Required, VDB Entry
- https://vuldb.com/?id.319369Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.622408Exploit, Third Party Advisory, VDB Entry
- https://github.com/jasper-software/jasper/issues/400Exploit, Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-8835?
How severe is CVE-2025-8835?
How do I fix CVE-2025-8835?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-8829A vulnerability was identified in Linksys RE6250, RE6300, RE…8.8
- CVE-2025-8830A vulnerability has been found in Linksys RE6250, RE6300, RE…8.8
- CVE-2025-8831A vulnerability was found in Linksys RE6250, RE6300, RE6350,…8.8
- CVE-2025-8832A vulnerability was determined in Linksys RE6250, RE6300, RE…8.8
- CVE-2025-8833A vulnerability was identified in Linksys RE6250, RE6300, RE…8.8
- CVE-2025-8834A vulnerability has been found in JCG Link-net LW-N915R 17s.…2.4
- CVE-2025-8836A vulnerability was determined in JasPer up to 4.2.5. Affect…3.3
- CVE-2025-8837A vulnerability was identified in JasPer up to 4.2.5. This a…7.8
- CVE-2025-8838A vulnerability has been found in WinterChenS my-site up to …9.8
- CVE-2025-8839A vulnerability was found in jshERP up to 3.5. This issue af…8.8
- CVE-2025-8840A vulnerability was determined in jshERP up to 3.5. Affected…5.4
- CVE-2025-8841A vulnerability was identified in zlt2000 microservices-plat…6.1
Are you affected by CVE-2025-8835?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
