VDB
Sign up
HIGH8.8

PYSEC-2026-2809

Out-of-bounds Write in OpenCV

Quick fix

PYSEC-2026-2809 — opencv-python: upgrade to the fixed version with the command below.

pip install --upgrade 'opencv-python>=3.3.1.11'

Details

OpenCV (Open Source Computer Vision Library) through 3.3 (corresponding to OpenCV-Python and OpenCV-Contrib-Python 3.3.0.9) has an invalid write in the cv::RLByteStream::getBytes function in modules/imgcodecs/src/bitstrm.cpp when reading an image file by using cv::imread, as demonstrated by the 2-opencv-heapoverflow-fseek test case.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/opencv-python
Introduced in: 0Fixed in: 3.3.1.11
Fixpip install --upgrade 'opencv-python>=3.3.1.11'

References