CVE-2026-48977
OpenSlide: Arbitrary memory write with crafted Ventana BIF file
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
OpenSlide is a C library for reading whole slide image files. From 3.4.1 until 4.0.1, OpenSlide's parse_level0_xml() processing in src/openslide-vendor-ventana.c accepts nonpositive row or column tile counts from a crafted Ventana BIF file. The invalid counts produce attacker-controlled relative memory offsets and allow arbitrary values to be written at those offsets, affecting all supported platforms and configurations and resulting in a crash or potential arbitrary code execution. This issue is fixed in version 4.0.1.
| CWE | CWE-123 CWE-823 CWE-1284 |
| Vendor | openslide |
| Product | openslide |
| Published | Sep 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for openslide openslide
Be the first to know when new unknown vulnerabilities affecting openslide openslide are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
openslide / openslide
>= 3.4.1, < 4.0.1
References
github.com: https://github.com/openslide/openslide/security/advisories/GHSA-mxg2-48g7-fmwc github.com: https://github.com/openslide/openslide/pull/751 github.com: https://github.com/openslide/openslide/commit/2be88bd782d9fff46de8e56a99baca523e7917b3 github.com: https://github.com/openslide/openslide/releases/tag/v4.0.1