PT-2026-58863 · Openhtj2K · Openhtj2K

CVE-2026-51808

·

Published

2026-07-14

·

Updated

2026-07-15

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenHTJ2K versions prior to 0.18.4
Description A buffer overflow allows an attacker to execute arbitrary code. The issue exists within the openhtj2k decoder impl::invoke, invoke line based, invoke line based stream, and invoke line based predecoded functions located in source/core/interface/decoder.cpp.
Recommendations Update OpenHTJ2K to a version newer than 0.18.4. As a temporary workaround, restrict the use of the openhtj2k decoder impl::invoke, invoke line based, invoke line based stream, and invoke line based predecoded functions.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-51808

Affected Products

Openhtj2K