๐Ÿ” CVE Alert

CVE-2026-51807

CRITICAL 9.8
CVSS Score
9.8
EPSS Score
0.5%
EPSS Percentile
38th

Heap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in OpenHTJ2K versions 0.18.3 and earlier (fixed in v0.18.4) caused by missing bounds validation before coding-pass lengths are written to j2k_codeblock::pass_length[128]. A crafted JPEG 2000 codestream containing malformed PPM packet headers can trigger a heap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in source/core/coding/coding_units.cpp due to missing bounds validation for the j2k_codeblock::pass_length[128] array which can lead to heap corruption and process termination.

Vendor n/a
Product n/a
Published Jul 14, 2026
Last Updated Jul 17, 2026
Stay Ahead of the Next One

Get instant alerts for n/a n/a

Be the first to know when new critical vulnerabilities affecting n/a n/a are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

n/a / n/a
n/a

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/osamu620/OpenHTJ2K/commit/0778b93 github.com: https://github.com/osamu620/OpenHTJ2K/blob/main/CHANGELOG github.com: https://github.com/osamu620/OpenHTJ2K/releases github.com: https://github.com/osamu620/OpenHTJ2K/compare/0778b93...v0.18.4