Junglewise Threat Intelligence

CVE-2026-51807: OpenHTJ2K heap buffer overflow in parse_packet_header

CVE-2026-51807 · Severity: info · CVSS 8.8 · Published 2026-07-14

Executive brief

OpenHTJ2K is an open-source library used for encoding and decoding High Throughput JPEG 2000 images, often used in high-performance imaging and medical applications. A security flaw in how the library handles image headers allows a specially crafted image file to trigger a memory overflow. If a user or server processes such a file, an attacker could potentially execute malicious code, steal sensitive data from memory, or crash the application.

Technical details

A heap buffer overflow exists in OpenHTJ2K v0.18.4 and earlier within the j2k_precinct_subband::parse_packet_header() function in source/core/coding/coding_units.cpp. The vulnerability is caused by a lack of bounds checking when adding segment_passes to the num_passes variable, which indexes the fixed-size j2k_codeblock::pass_length[128] array. An attacker can provide a malformed J2K/JP2 file or JPIP/JPP client response that exceeds this 128-element limit, leading to out-of-bounds writes on the heap. This can result in arbitrary code execution, server-side heap information leaks, or application crashes. The issue was addressed in version 0.19.0 (and specifically fixed in the commit 0778b93).

Affected products

  • osamu620 OpenHTJ2K 0.18.4 and earlier

Timeline

  • 2026-07-14: advisory: NVD publication date
  • 2026-05-30: patched: Fixed in version 0.19.0 and commit 0778b93

References

Related threats