VDB
Sign up
HIGH8.8

PYSEC-2026-725

Out-of-bounds Write in OpenCV

Quick fix

PYSEC-2026-725 — opencv-contrib-python-headless: upgrade to the fixed version with the command below.

pip install --upgrade 'opencv-contrib-python-headless>=4.2.0.32'

Details

An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, version 4.1.0 (corresponds with OpenCV-Python version 4.1.2.30). A specially crafted JSON file can cause a buffer overflow, resulting in multiple heap corruptions and potentially code execution. An attacker can provide a specially crafted file to trigger this vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/opencv-contrib-python-headless
Introduced in: 0Fixed in: 4.2.0.32
Fixpip install --upgrade 'opencv-contrib-python-headless>=4.2.0.32'

References