HIGH7.5
PYSEC-2026-2798
Out-of-bounds Read and Out-of-bounds Write in OpenCV
Quick fix
PYSEC-2026-2798 — opencv-contrib-python: upgrade to the fixed version with the command below.
pip install --upgrade 'opencv-contrib-python>=3.4.7.28'Details
An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1 (OpenCV-Python before 3.4.7.28 and 4.x before 4.1.1.26). There is an out of bounds read/write in the function HaarEvaluator::OptFeature::calc in modules/objdetect/src/cascadedetect.hpp, which leads to denial of service.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/opencv-contrib-python
Introduced in:
0Fixed in: 3.4.7.28Fix
pip install --upgrade 'opencv-contrib-python>=3.4.7.28'References
- https://nvd.nist.gov/vuln/detail/CVE-2019-14492[ADVISORY]
- https://github.com/opencv/opencv/issues/15124[WEB]
- https://github.com/opencv/opencv-python[PACKAGE]
- https://github.com/opencv/opencv/compare/33b765d...4a7ca5a[WEB]
- https://github.com/opencv/opencv/compare/371bba8...ddbd10c[WEB]
- http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00025.html[WEB]
- https://pypi.org/project/opencv-contrib-python[PACKAGE]
- https://github.com/advisories/GHSA-fw99-f933-rgh8[ADVISORY]