Integer overflow in Openimageio - #VU129719
Published: May 5, 2026
Openimageio
AcademySoftwareFoundation
Description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to integer overflow or wraparound in the JPEG2000 reader buffer allocation in jpeg2000input.cpp when parsing a crafted JPEG2000 file with large dimensions. A remote attacker can supply a specially crafted JPEG2000 file to execute arbitrary code.
Only builds compiled with the USE_OPENJPH flag are vulnerable. User interaction is required to open the crafted file.