Comment by _ache_

2 days ago

I can confirm. I found multiple problems in the "official" cjxl encoder back in 2023 contrary to the webp2 (cwp2) implementation where I could not find any bug or error.

If the encoder have obvious problems it is not a big deal, but it doesn't bode well for the decoder.

CVE-2023-0645 in libjxl that year too, and several since

  • It's also a horrible API. Will start working on the rust lib then. Hopefully it's better, because I really want to use it.