CVE-2026-51808
the affected product
Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary code via the openhtj2k_decoder_impl::invoke, invoke_line_based, invoke_line_based_stream, and invoke_line_based_predecoded function in source/core/interface/decoder.cpp
- CVSS
- 9.8
- EPSS
- 0.48% 38.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.15