Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-51808: OpenHTJ2K: Buffer overflow lets attackers run malicious code

CVE-2026-51808 CVE-2026-51808
Summary

A vulnerability in OpenHTJ2K versions 0.18.4 and earlier allows attackers to run unauthorized code on a system. This could lead to data theft or system compromise. Update to the latest version of OpenHTJ2K to fix this issue.

Original title
Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary code via the openhtj2k_decoder_impl::invoke, invoke_line_based, invoke_line_based_stream, and ...
Original description
Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary code via the openhtj2k_decoder_impl::invoke, invoke_line_based, invoke_line_based_stream, and invoke_line_based_predecoded function in source/core/interface/decoder.cpp
Vulnerability type
CWE-120 Classic Buffer Overflow
Published: 14 Jul 2026 · Updated: 20 Jul 2026 · First seen: 14 Jul 2026