CVE-2026-51807
A heap-based out-of-bounds write exists in OpenHTJ2K 0.18.3 and earlier. The flaw is triggered by a crafted JPEG 2000 file that causes memory corruption. It can crash the process or lead to arbitrary code execution.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
OpenHTJ2K library versions 0.18.3 and earlier. Users who process JPEG 2000 images with this library are affected.
Real-world impact
An attacker can supply a malicious JPEG 2000 file to corrupt memory, potentially crashing the application or executing arbitrary code.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability can be exploited remotely without authentication or user interaction, and it can compromise confidentiality, integrity, and availability.
What to do about it
- 011. Upgrade OpenHTJ2K to version 0.18.4 or later.
- 022. Restart any services using OpenHTJ2K.
NVD-referenced vendor advisory
Timeline
- Jul 15, 2026 · 19d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 17, 2026 · 16d agoAdvisory updatedThe NVD record was last revised.
- Jul 19, 2026 · 15d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.