Hello!
During some fuzz-testing of jpeg2png, I identified two classes of reproducible denial-of-service vulnerabilities that can be triggered by any caller processing JPEG files from untrusted sources. Since I couldn't find a SECURITY.md or a security policy, I'm opening this issue to ask about the preferred channel for responsible disclosure before sharing the full details (POC files, ASan traces, reproducer steps).
Hello!
During some fuzz-testing of jpeg2png, I identified two classes of reproducible denial-of-service vulnerabilities that can be triggered by any caller processing JPEG files from untrusted sources. Since I couldn't find a SECURITY.md or a security policy, I'm opening this issue to ask about the preferred channel for responsible disclosure before sharing the full details (POC files, ASan traces, reproducer steps).